Sophos

W32/VB-DZJ

Aliases
  • TR/VB.FK
  • W32.SillyWNSE
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from June 2008 (4.30)
Protection available since 24 April 2008 01:55:53 (GMT)
Detected by All Sophos products

Action

More Information

W32/VB-DZJ attempts to spread by copying itself to available network drives.

When first run W32/VB-DZJ copies itself to <System>\WinSevices.exe and creates the folder <Current Folder>\WinSevic.

Folder WinSevic contains several text files ending with the extension "pdf" e.g. "Spiderman 2.pdf", "Java Telephony.pdf". These files all contain the message:

"Please use this Link:<url> to search From Google.com".

The folder WinSevic and all the files inside the folder can be safely deleted.

The following registry entries are created to run WinSevices.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
regManager
<System>\WinSevices.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
regManager
<System>\WinSevices.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer