Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | May 2008 (4.29) |
| Protection available since | 25 March 2008 15:42:27 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/VB-DYY is a worm for the Windows platform.
W32/VB-DYY spreads to other network computers.
When first run W32/VB-DYY copies itself to:
<Root>\Documente und Einstellungen\Orkut.exe
<Root>\Documenti e Impostazioni\Orkut.exe
<Root>\Documents and Settings\Orkut.exe
<Root>\Games\Orkut.exe
<Root>\Inetpub\Orkut.exe
<Root>\My Documents\Orkut.exe
<Root>\My Downloads\index.exe
<Root>\My Music\song.exe
<Root>\My Shared Folder\Orkut.exe
<CurrentFolder>\as.exe
<Root>\Programma's\Orkut.exe
<Root>\Programmi\Orkut.exe
<Root>\Programs\Orkut.exe
<Windows>\Orkut.exe
<Root>\mijn documenten\Orkut.exe
<Root>\mirc\aliases.exe
<Root>\mirc32\mirc.exe
<Root>\pirc98\events.exe
<Root>\programme\Orkut.exe
<Windows>\0.exe
<System>\New Folder.exe
and creates the file <Temp>\~dfb4bf.tmp.
The following registry entry is set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
userinit.exe,New Folder.exe
