Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 16 July 2008 01:53:35 (GMT) |
| Last updated | 16 July 2008 06:51:38 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
VBS/Sasan-G overwrites every VB Script file on the computer. These files are no longer recoverable and need to be restored from backup.
More Information
VBS/Sasan-G overwrites every VB Script file on the computer with a copy of itself. These files are no longer recoverable.
VBS/Sasan-G creates a companion vbs file for every .bmp, .doc, .xls, .ppt file on the computer. These companion files are also detected as VBS/Sasan-G.
VBS/Sasan-G copies itself to removable media and creates the file autorun.inf. Autorun.inf is detected as VBS/Sasan-Fam.
VBS/Sasan-G sets the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFilesAssociate
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegedit
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
VBS/Sasan-G sets the following registry entries to "Notepad.exe" which disables the corresponding applications:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regdt32.exe
Debugger
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TaskMgr.exe
Debugger
