Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for disinfecting macro viruses.
Please read the instructions for removing worms.
More Information
VBS/Britney-A is a mass-mailing worm which spreads via both Microsoft Outlook and IRC networks. The worm copies itself to BRITNEY.CHM in the Windows folder and then emails itself to the first address in the Outlook address list. The email will have the following characteristics:
Subject Line: RE: Britney Pics
Body Text: Take a look at these pics ...
Attachment: BRITNEY.CHM
The worm requires ActiveX to be enabled for the VBS to run and so it prompts the user to enable ActiveX with the message "Enable ActiveX To See Britny Pictures".
VBS/Britney-A searches the C:, D: and E: drives for the presence of a file called MIRC.INI. If it finds a file of this name then the worm creates a SCRIPT.INI file which will then attempt to send copies of the files to other IRC users.
SCRIPT.INI will be detected by Sophos Anti-Virus as mIRC/Simp-Fam.


