Antivirus and Security Software from Sophos

Sophos blogs

VBS/Appix-E

Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for disinfecting macro viruses.

Please read the instructions for removing infected executable files.

Windows NT/2000/XP

In Windows NT/2000/XP you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

and delete it if it exists.

Close the registry editor.

More Information

VBS/Appix-E is a VBScript virus dropped by W32/Appix-E.

VBS/Appix-E spreads by prepending VBS files and by emailing itself to all addresses in the Microsoft Outlook address list.

VBS/Appix-E drops a copy of itself in the Windows folder as APPBOOST.VBS and may add an entry in the registry at

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

to run itself on system restart.

Emails have the following characteristics:

Subject line: "Application Booster"

Message text: "Try the Free Application Boost Pack, NOW !!!!"

Attached file: APPBOOST.EXE

VBS/Appix-E also attaches the files APPBOOST.REG and APPBOOST.EXE if they exist in the Windows folder.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer