Sophos

VBS/SillyAV-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 30 January 2008 20:09:06 (GMT)
Last updated 8 February 2008 10:22:57 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

VBS/SillyAV-A is a Visual Basic Script worm which spreads by copying itself to removable devices.

VBS/SillyAV-A claims to be repair tool for virus attacks but by its own admission it spreads like a worm.

VBS/SillyAV-A copies itself to <System>\VirusRemoval.vbs and modifies the following registry entry to run itself system restart:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\wscript.exe <System>\VirusRemoval.vbs

VBS/SillyAV-A sets the following registry entries:

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000000

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000000

VBS/SillyAV-A may also modify various registry setting related to Microsoft Internet Explorer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer