Sophos

W32/VB-DYY

Aliases
  • Trojan-Dropper.Win32.VB.ug
  • Generic BackDoor.k
  • Win32/VB.NJB
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Included in our products from May 2008 (4.29)
Protection available since 25 March 2008 15:42:27 (GMT)
Detected by All Sophos products

Action

More Information

W32/VB-DYY is a worm for the Windows platform.

W32/VB-DYY spreads to other network computers.

When first run W32/VB-DYY copies itself to:

<Root>\Documente und Einstellungen\Orkut.exe
<Root>\Documenti e Impostazioni\Orkut.exe
<Root>\Documents and Settings\Orkut.exe
<Root>\Games\Orkut.exe
<Root>\Inetpub\Orkut.exe
<Root>\My Documents\Orkut.exe
<Root>\My Downloads\index.exe
<Root>\My Music\song.exe
<Root>\My Shared Folder\Orkut.exe
<CurrentFolder>\as.exe
<Root>\Programma's\Orkut.exe
<Root>\Programmi\Orkut.exe
<Root>\Programs\Orkut.exe
<Windows>\Orkut.exe
<Root>\mijn documenten\Orkut.exe
<Root>\mirc\aliases.exe
<Root>\mirc32\mirc.exe
<Root>\pirc98\events.exe
<Root>\programme\Orkut.exe
<Windows>\0.exe
<System>\New Folder.exe

and creates the file <Temp>\~dfb4bf.tmp.

The following registry entry is set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
userinit.exe,New Folder.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer