Sophos

W32/Isetspy-B

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Included in our products from April 2008 (4.28)
Protection available since 9 February 2008 03:08:01 (GMT)
Last updated 18 February 2008 11:21:21 (GMT)
Detected by All Sophos products

Action

More Information

W32/Isetspy-B is a worm for the Windows platform.

When run W32/Isetspy-B installs the following files:
<Profile>\Application Data\dxdlls\dxdlg.exe
<Profile>\Application Data\dxdlls\imapd.exe
<Profile>\Application Data\dxdlls\imapdb.dll
<Profile>\Application Data\dxdlls\imapdb.exe
<Profile>\Application Data\dxdlls\imapdc.dll
<Profile>\Application Data\dxdlls\imapdd.dll
<Profile>\Application Data\dxdlls\imapde.dll
<Profile>\Application Data\dxdlls\boot.vbs
<System>\wproxp.exe
<System>\rbwinx1.dll
<System>\boot.vbs
<System>\imapd.exe
<System>\imapdb.dll
<System>\imapdb.exe
<System>\imapdc.dll
<System>\imapdd.dll
<System>\imapde.dll
<System>\dxdlg.exe

Boot.vbs is detected as W32/Isetspy-B.
rbwinx1.dll is a data file and may be safelydeleted.
All other files are detected as Mal/EncPk-AO.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer