Sophos

W32/ParaDrop-A

Aliases
  • Trojan-Dropper.Win32.Paradrop.a
  • W32/Polybot.dr
  • PE_AGOBOT.AQM
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 30 June 2005 06:37:10 (GMT)
Detected by All Sophos products

Action

More Information

W32/ParaDrop-A is a multi-component network worm.

W32/ParaDrop-A drops two files to the Windows system folder, scvhost.exe and iexplore.exe. Scvhost.exe is a member of the W32/Agobot family of worms and iexplore.exe is a member of the W32/Poebot family of network worms, and it is this latter file that spreads W32/ParaDrop-A to network shares with weak passwords and via network security exploits.

svchost.exe is detected as W32/Agobot-AAE
iexplore.exe is detected as W32/Poebot-Gen
iexplore.exe may also be infected with W32/Parite-B

The following registry entries are created:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Configuration Loader
svchost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Internet Explorer
iexplore.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer