Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 20 December 2006 23:59:12 (GMT) |
| Last updated | 18 January 2007 09:30:58 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/VB-NIA is a worm for the Windows platform.
W32/VB-NIA spreads via removable storage disks.
When first run W32/VB-NIA copies itself to \Tmp\Isass.exe and creates the following files:
Autorun.inf
Surat Untuk Edelin.txt
The file \Tmp\Isass.exe is hidden. The inf and txt files can be deleted.
The following registry entry is created to start the worm automatically on
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
EDxMC110
\Tmp\Isass.exe
The worm can also
- disable system utilities such as regedit, command prompt and taskmanager
- enable the "Do not show Hidden and system files" option in Folder options
- disable "Folder options" from the Tools menu in Explorer
