Sophos

W32/VB-NIA

Aliases
  • Virus.Win32.VB.ce
  • W32/Sillyworm.VE
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 December 2006 23:59:12 (GMT)
Last updated 18 January 2007 09:30:58 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/VB-NIA is a worm for the Windows platform.

W32/VB-NIA spreads via removable storage disks.

When first run W32/VB-NIA copies itself to \Tmp\Isass.exe and creates the following files:

Autorun.inf
Surat Untuk Edelin.txt

The file \Tmp\Isass.exe is hidden. The inf and txt files can be deleted.

The following registry entry is created to start the worm automatically on
startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
EDxMC110
\Tmp\Isass.exe

The worm can also
- disable system utilities such as regedit, command prompt and taskmanager
- enable the "Do not show Hidden and system files" option in Folder options
- disable "Folder options" from the Tools menu in Explorer

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer