Sophos

W32/VB-DZA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 31 March 2008 14:06:39 (GMT)
Detected by All Sophos products

Action

More Information

W32/VB-DZA is a worm for the Windows platform.

When first run W32/VB-DZA copies itself to:

<Root>\DAT1155687.sys
<User>\Cookies\Cookies.exe
<Desktop>\New Arial Kotim.exe
<Startup>\Adobe Gamma L0ader.exe
<Root>\^$4!N$^.exe
<My Documents>\My Music .exe
<My Documents>\My Pictures .exe

The hidden file ^$4!N$^.exe is also copied to any folder that is browsed to using Explorer.

The folders "My Music" and "My Pictures" in "My Documents" are set to hidden.

The following registry entries are created to run Cookies.exe and New Arial Kotim.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Scan Fonts
<Desktop>\New Arial Kotim.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Clean Cookies
<User>\Cookies\Cookies.exe

The following registry entry is also created:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Yeah
D:\^$4!N$^.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer