Sophos

VBS/Yosenio-A

Aliases
  • Email-Worm.Win32.Yosenio.a
  • W32/Yesenio.worm!vbs
  • VBS_ENTICE.D
  • W32.Ainesey.A@mm!vbs
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 6 April 2005 20:41:19 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing infected executable files.

You will also need to edit the following registry entry, if it is present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

and remove any reference to any file you deleted.

Close the registry editor.

More Information

VBS/Yosenio-A is an polymorphic overwriting virus that drops a mass-mailing worm.

VBS/Yosenio-A searches drives recursively for files with certain file extensions. The virus overwrites files with VBS and VBE extensions. The virus also overwrites files with JS, JSE, CSS, WSH, SCT, HTF, MP3 and WMS extensions, appending '.VBS' to the filename when it does so.

VBS/Yosenio-A copies itself to the Windows folder as WINEXEC.EXE.VBS and drops and runs the mass-mailing worm W32/Yosenio-A as MSIEXEC32.EXE in the Windows folder.

VBS/Yosenio-A creates the following registry entries in order to run itself and the dropped file on startup:

HKLM\SYSTEM\Microsoft\Windows\CurrentVersion\RunServices
MSIEXEC
<Windows>\MSIEXEC.EXE

HKLM\SYSTEM\Microsoft\Windows\CurrentVersion\RunServices
WINEXEC
<Windows>\WINEXEC.EXE.VBS

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer