W32/VB-GFU

Category: Viruses and Spyware Protection available since:05 Dec 2012 05:54:35 (GMT)
Type: Win32 worm Last Updated:05 Dec 2012 05:54:35 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/VB-GFU exhibits the following characteristics:

File Information

Size
264K
SHA-1
7a68fc16fd1e4cb987ae2cde5f0e071b45f221bb
MD5
05ba517e808b21bec9e30c792a93a3b0
CRC-32
3d364164
File type
Windows executable
First seen
2012-12-04

Runtime Analysis

Copies Itself To
  • F:/Passwords.exe
  • F:/Porn.exe
  • F:/Secret.exe
  • F:/Sexy.exe
  • F:/sujip.exe
  • c:\Documents and Settings\test user\sujip.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    sujip
    c:\Documents and Settings\test user\sujip.exe /c
  • HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    NoAutoUpdate
    0x00000001
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    ShowSuperHidden
    0x00000000
Processes Created
  • c:\Documents and Settings\test user\sujip.exe

download Try Sophos products for free
Download now