Sophos

VBS/Mondez-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Included in our products from July 2008 (4.31)
Protection available since 9 May 2008 23:49:11 (GMT)
Detected by All Sophos products

Action

More Information

VBS/Mondez-A is a virus for the Windows platform.

VBS/Mondez-A attempts to infect files with an extension of HTM, HTML and HTT, writing its own code to the end.

VBS/Mondez-A attempts to steal the user's Yahoo! Messenger user id and contact list, and send it by email to a remote address. VBS/Mondez-A also attempts to send the following email to all the contacts:

Sender:
  
  <user's id>@yahoo.com

Subject:
  
  Best Site in IRAN

Message text:

  Hello
  
  This is only for Proxy and Sexy for all Iran Boys: <domain removed>

VBS/Mondez-A modifies the following registry entry in order to change the user's start page:

HKCU\Software\Microsoft\Internet Explorer\Main
Start Page

VBS/Mondez-A drops the files <System>\Kernel.vbs and <System>\TSP32v.dll, both of which are detected as VBS/Mondez-A.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer