Sophos

VBS/Sasan-G

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 16 July 2008 01:53:35 (GMT)
Last updated 16 July 2008 06:51:38 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.


VBS/Sasan-G overwrites every VB Script file on the computer. These files are no longer recoverable and need to be restored from backup.

More Information

VBS/Sasan-G overwrites every VB Script file on the computer with a copy of itself. These files are no longer recoverable.

VBS/Sasan-G creates a companion vbs file for every .bmp, .doc, .xls, .ppt file on the computer. These companion files are also detected as VBS/Sasan-G.

VBS/Sasan-G copies itself to removable media and creates the file autorun.inf. Autorun.inf is detected as VBS/Sasan-Fam.

VBS/Sasan-G sets the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFilesAssociate

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegedit

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr

VBS/Sasan-G sets the following registry entries to "Notepad.exe" which disables the corresponding applications:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regdt32.exe
Debugger

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TaskMgr.exe
Debugger

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer