Virus:Worm/Ranchneg.A
Date discovered:23/05/2006
Type:Worm
In the wild:Yes
Reported Infections:Medium
Distribution Potential:Medium
Damage Potential:Medium
Static file:Yes
File size:46.626 Bytes
MD5 checksum:6d1c9334017614671b83d139e8de0534
VDF version:6.34.01.128
IVDF version:6.34.01.133 - Wednesday, May 24, 2006

 General Methods of propagation:
   • Email
   • Local network


Aliases:
   •  Symantec: W32.Banwarum@mm
   •  Mcafee: W32/Banwarum@MM
   •  Kaspersky: Email-Worm.Win32.Banwarum.a
   •  TrendMicro: WORM_RANCHNEG.A
   •  F-Secure: Email-Worm.Win32.Banwarum.a
   •  Sophos: W32/Zasran-A
   •  Panda: W32/Banwarum.A.worm
   •  Grisoft: I-Worm/Zasran.A
   •  VirusBuster: I-Worm.Banwarum.A
   •  Eset: Win32/Banwarum.A
   •  Bitdefender: Win32.Ranchneg.A@mm

It was previously detected as:
   •  TR/Ranchneg.A

Similar detection:
   •  W32/Zasran.A
   •  Win32.Zasrancheg


Platforms / OS:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Drops a malicious file
   • Uses its own Email engine
   • Registry modification
   • Makes use of software vulnerability
Description inserted by Alexander Vukcevic on Tuesday, May 23, 2006
Description updated by Oliver Auerbach on Wednesday, May 31, 2006

Back . . . .