Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | August 2008 (4.32) |
| Protection available since | 24 June 2008 01:03:42 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/VB-EAD drops and registers the file <System>\mswinsck.ocx which is a clean Microsoft ActiveX control.
W32/VB-EAD copies itself to <Windows>\systemm4.exe
W32/VB-EAD creates the following files:
<Root>\boot.vbs - also detected as W32/VB-EAD
<Root>\autorun.inf - also detected as W32/VB-EAD
W32/VB-EAD creates the registry value
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sys
<Windows>\systemm4.exe
