Sophos

W32/Britney-B

Aliases
  • TROJ_BRITY.A
  • W32.Britney
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 6 September 2004 10:04:02 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Editing Win.ini

At the taskbar, click Start|Run and type Sysedit. Bring Win.ini to the front. In the [windows] section, search for a line beginning with 'Run=' and delete any references to the files you removed. Delete only that reference, not any other text.

Reboot your computer.

More Information

W32/Britney-B is a worm that spreads by copying itself to the A: drive as the file Britney.exe. W32/Britney-B is a worm that spreads by copying itself to the A: drive as the file Britney.exe.

In order to be started automatically when Windows boots up W32/Britney-B may copy itself to the file c:\windows\system\user32.exe. and add a Run entry to the Win.ini file pointing to this file.

The worm also adds the registry entry:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

pointing to this file.

In addition W32/Britney-B creates the text file C:\windows\system\User32.ini.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer