Saturday, August 20, 2005

W32.Nanpy.A

Nanpy A, W32.Nanpy.A, is a Windows worm, which spreads to vulnerable computers via the RPC-DCOM exploit. Nanpy attempts to redirect access to various web sites by modifying the hosts file and makes a copy of itself in the Windows System folder. It also creates a registry key to run this file on re-boot.