Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | August 2005 (3.96) |
| Protection available since | 30 June 2005 06:37:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/ParaDrop-A is a multi-component network worm.
W32/ParaDrop-A drops two files to the Windows system folder, scvhost.exe and iexplore.exe. Scvhost.exe is a member of the W32/Agobot family of worms and iexplore.exe is a member of the W32/Poebot family of network worms, and it is this latter file that spreads W32/ParaDrop-A to network shares with weak passwords and via network security exploits.
svchost.exe is detected as W32/Agobot-AAE
iexplore.exe is detected as W32/Poebot-Gen
iexplore.exe may also be infected with W32/Parite-B
The following registry entries are created:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Configuration Loader
svchost.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Internet Explorer
iexplore.exe
