Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | July 2008 (4.31) |
| Protection available since | 9 May 2008 23:49:11 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting macro viruses.
More Information
VBS/Mondez-A is a virus for the Windows platform.
VBS/Mondez-A attempts to infect files with an extension of HTM, HTML and HTT, writing its own code to the end.
VBS/Mondez-A attempts to steal the user's Yahoo! Messenger user id and contact list, and send it by email to a remote address. VBS/Mondez-A also attempts to send the following email to all the contacts:
Sender:
<user's id>@yahoo.com
Subject:
Best Site in IRAN
Message text:
Hello
This is only for Proxy and Sexy for all Iran Boys: <domain removed>
VBS/Mondez-A modifies the following registry entry in order to change the user's start page:
HKCU\Software\Microsoft\Internet Explorer\Main
Start Page
VBS/Mondez-A drops the files <System>\Kernel.vbs and <System>\TSP32v.dll, both of which are detected as VBS/Mondez-A.
