Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 30 January 2008 20:09:06 (GMT) |
| Last updated | 8 February 2008 10:22:57 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
VBS/SillyAV-A is a Visual Basic Script worm which spreads by copying itself to removable devices.
VBS/SillyAV-A claims to be repair tool for virus attacks but by its own admission it spreads like a worm.
VBS/SillyAV-A copies itself to <System>\VirusRemoval.vbs and modifies the following registry entry to run itself system restart:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\wscript.exe <System>\VirusRemoval.vbs
VBS/SillyAV-A sets the following registry entries:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000000
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000000
VBS/SillyAV-A may also modify various registry setting related to Microsoft Internet Explorer.
