Sophos

Troj/VB-IW

Aliases
  • Backdoor.Win32.VB.agb
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 25 July 2005 04:50:44 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/VB-IW is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

When first run Troj/VB-IW copies itself to:

<System>\word.exe
<Windows>\system\regedit.exe

The following registry entries are created to run Troj/VB-IW on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
KV2005
<System>\word.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
KV2005
<System>\word.EXE

The Trojan creates a copy of MSWINSCK.OCX with the following filename:

<System>\~sysWord.tam

This file may be deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer