Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 31 March 2008 14:06:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/VB-DZA is a worm for the Windows platform.
When first run W32/VB-DZA copies itself to:
<Root>\DAT1155687.sys
<User>\Cookies\Cookies.exe
<Desktop>\New Arial Kotim.exe
<Startup>\Adobe Gamma L0ader.exe
<Root>\^$4!N$^.exe
<My Documents>\My Music .exe
<My Documents>\My Pictures .exe
The hidden file ^$4!N$^.exe is also copied to any folder that is browsed to using Explorer.
The folders "My Music" and "My Pictures" in "My Documents" are set to hidden.
The following registry entries are created to run Cookies.exe and New Arial Kotim.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Scan Fonts
<Desktop>\New Arial Kotim.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Clean Cookies
<User>\Cookies\Cookies.exe
The following registry entry is also created:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Yeah
D:\^$4!N$^.exe
