Antivirus and Security Software from Sophos

Sophos blogs

W32/VBSilly-D

Aliases
  • P2P-Worm.Win32.VB.cp
  • W32/KSQ.A@p2p
  • W32.SillyP2P
  • Win32/VB.CP
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Peer-to-peer
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 September 2006 17:57:12 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/VBSilly-D is a worm for the Windows platform.

W32/VBSilly-D spreads via file sharing on P2P networks.

When first run W32/VBSilly-D copies itself to:

<Windows system folder>\skq\skq.exe
<Windows folder>\Software Kings and queens\(Tool) IP Scanner.exe
<Windows folder>\Software Kings and queens\[APP] MSN Control - Best hacking program for msn.exe
<Windows folder>\Software Kings and queens\[App] Sims 2 Nude crack.exe
<Windows folder>\Software Kings and queens\AbsoluteFTP Keygen.exe
<Windows folder>\Software Kings and queens\Ad-Aware Pro crack.exe
<Windows folder>\Software Kings and queens\AD Remover.exe
<Windows folder>\Software Kings and queens\Adobe Universal keygen by (Sinfo).exe
<Windows folder>\Software Kings and queens\Age of Empire crack.exe
<Windows folder>\Software Kings and queens\All ea games keygen.exe
<Windows folder>\Software Kings and queens\AOL Password Hacker.exe
<Windows folder>\Software Kings and queens\Aurobat 6 pro crack.exe
<Windows folder>\Software Kings and queens\Aurobat Reader Activator (ALL).exe
<Windows folder>\Software Kings and queens\Battle net keygen.exe
<Windows folder>\Software Kings and queens\Battlefield Vietnam crack.exe
<Windows folder>\Software Kings and queens\Beyond Good And evil crack.exe
<Windows folder>\Software Kings and queens\Broken Sword 3 crack.exe
<Windows folder>\Software Kings and queens\C&C Generals crack.exe
<Windows folder>\Software Kings and queens\Castle Wolfstein Expansion crack.exe
<Windows folder>\Software Kings and queens\CD Ripper (Easy to use).exe
<Windows folder>\Software Kings and queens\Clone CD 6 crack.exe
<Windows folder>\Software Kings and queens\COD UO crack.exe
<Windows folder>\Software Kings and queens\Command and Conquer Renagade crack.exe
<Windows folder>\Software Kings and queens\Commandos 3 crack.exe
<Windows folder>\Software Kings and queens\Conflict Desert Storm 2 crack.exe
<Windows folder>\Software Kings and queens\Counter Strike online crack.exe
<Windows folder>\Software Kings and queens\Crasy Taxi crack.exe
<Windows folder>\Software Kings and queens\CSI crack.exe
<Windows folder>\Software Kings and queens\DC++ ID hacker.exe
<Windows folder>\Software Kings and queens\DirectX 9 downloader.exe
<Windows folder>\Software Kings and queens\Doom 3 crack.exe
<Windows folder>\Software Kings and queens\Download Accelerator.exe
<Windows folder>\Software Kings and queens\F1 2004 crack.exe
<Windows folder>\Software Kings and queens\Farcry crack.exe
<Windows folder>\Software Kings and queens\FBI hacker tool.exe
<Windows folder>\Software Kings and queens\Fifa 2005 crack.exe
<Windows folder>\Software Kings and queens\Fight night crack.exe
<Windows folder>\Software Kings and queens\Final Fantasy keygens.exe
<Windows folder>\Software Kings and queens\Flow crack.exe
<Windows folder>\Software Kings and queens\Football Manager 2005 crack.exe
<Windows folder>\Software Kings and queens\Free SMS mobile sender (Nokia Only).exe
<Windows folder>\Software Kings and queens\GameCube Emulator.exe
<Windows folder>\Software Kings and queens\Ghost File maker.exe
<Windows folder>\Software Kings and queens\Half Life 2 crack by Firekolom.exe
<Windows folder>\Software Kings and queens\HALO Combat Evolved crack.exe
<Windows folder>\Software Kings and queens\Harry Potter crack.exe
<Windows folder>\Software Kings and queens\Hitman 2 crack.exe
<Windows folder>\Software Kings and queens\hitman contracts crack.exe
<Windows folder>\Software Kings and queens\Hooligans crack.exe
<Windows folder>\Software Kings and queens\Hotmail hacker.exe
<Windows folder>\Software Kings and queens\Hoyle casino 2004 crack.exe
<Windows folder>\Software Kings and queens\IL2 SFB crack.exe
<Windows folder>\Software Kings and queens\ISS Pro 3 crack.exe
<Windows folder>\Software Kings and queens\James bond - night fire crack.exe
<Windows folder>\Software Kings and queens\Kazaa PopUp Blocker.exe
<Windows folder>\Software Kings and queens\Kazaa Spyware remover.exe
<Windows folder>\Software Kings and queens\KOEI Winning Post 6 crack.exe
<Windows folder>\Software Kings and queens\Lame MP3 Encoder 3.92.exe
<Windows folder>\Software Kings and queens\Macromedia Software keygen.exe
<Windows folder>\Software Kings and queens\Mafia crack.exe
<Windows folder>\Software Kings and queens\Master & Slave crack.exe
<Windows folder>\Software Kings and queens\Max Payne crack.exe
<Windows folder>\Software Kings and queens\Mcafee crack.exe
<Windows folder>\Software Kings and queens\Medal Of Honor PA crack.exe
<Windows folder>\Software Kings and queens\Microsoft Flight Simulator 2004 crack.exe
<Windows folder>\Software Kings and queens\Microsoft Rallysport challenge crack.exe
<Windows folder>\Software Kings and queens\MOH spearhead crack.exe
<Windows folder>\Software Kings and queens\monkey Island 4 crack.exe
<Windows folder>\Software Kings and queens\Moto GP 2004 crack.exe
<Windows folder>\Software Kings and queens\Nascar Thunder 2004 crack.exe
<Windows folder>\Software Kings and queens\NBA Live 2004 crack.exe
<Windows folder>\Software Kings and queens\Need for speed underground 2 crack.exe
<Windows folder>\Software Kings and queens\NFSU 2 crack.exe
<Windows folder>\Software Kings and queens\Norton Antivirus 2005 crack.exe
<Windows folder>\Software Kings and queens\Norton Internet secutity 2005 crack.exe
<Windows folder>\Software Kings and queens\PainKiller crack.exe
<Windows folder>\Software Kings and queens\PhotoShop keygen.exe
<Windows folder>\Software Kings and queens\Pinnacle studio 9 crack.exe
<Windows folder>\Software Kings and queens\Pirates of the caribbean crack.exe
<Windows folder>\Software Kings and queens\Power Archiver crack.exe
<Windows folder>\Software Kings and queens\Praetorians crack.exe
<Windows folder>\Software Kings and queens\Prince of Persia crack.exe
<Windows folder>\Software Kings and queens\Princess crack.exe
<Windows folder>\Software Kings and queens\Prisoner Of War crack.exe
<Windows folder>\Software Kings and queens\Pro Beach Soccer crack.exe
<Windows folder>\Software Kings and queens\Pro Evolution Soccor 4 crack.exe
<Windows folder>\Software Kings and queens\PS2 emulator.exe
<Windows folder>\Software Kings and queens\Quake 3 Arena crack.exe
<Windows folder>\Software Kings and queens\Raingow Six 3 crack.exe
<Windows folder>\Software Kings and queens\Red Faction crack.exe
<Windows folder>\Software Kings and queens\Resedent evil game crack.exe
<Windows folder>\Software Kings and queens\Rice Of nation crack.exe
<Windows folder>\Software Kings and queens\Richard Burns Rally crack.exe
<Windows folder>\Software Kings and queens\Robin Hood crack.exe
<Windows folder>\Software Kings and queens\Roller Coaster tycoon 3 crack.exe
<Windows folder>\Software Kings and queens\Rome total war crack.exe
<Windows folder>\Software Kings and queens\Router Internet Booster.exe
<Windows folder>\Software Kings and queens\Shrek 2 crack.exe
<Windows folder>\Software Kings and queens\SimCity 4 crack.exe
<Windows folder>\Software Kings and queens\Sinji Mp3 Splitter.exe
<Windows folder>\Software Kings and queens\SOF crack.exe
<Windows folder>\Software Kings and queens\Spell Force - The Order of dawn.exe
<Windows folder>\Software Kings and queens\Spiderman 2 crack.exe
<Windows folder>\Software Kings and queens\Star wars - Jedi knight - Jedi Academy crack.exe
<Windows folder>\Software Kings and queens\Star Wars - knights of the old republic crack.exe
<Windows folder>\Software Kings and queens\Star Wars Battefront crack.exe
<Windows folder>\Software Kings and queens\Starsky & Hutch crack.exe
<Windows folder>\Software Kings and queens\Super DVD Ripper 3.7.exe
<Windows folder>\Software Kings and queens\SVCD codecs.exe
<Windows folder>\Software Kings and queens\Syberia crack.exe
<Windows folder>\Software Kings and queens\Sysmantec keygen.exe
<Windows folder>\Software Kings and queens\The sims 2 crack.exe
<Windows folder>\Software Kings and queens\Tiger woods PGA tour 2004 crack.exe
<Windows folder>\Software Kings and queens\Tropico 2 crack.exe
<Windows folder>\Software Kings and queens\Unreal Tournament 2004 crack.exe
<Windows folder>\Software Kings and queens\Urban Freestyle Soccer crack.exe
<Windows folder>\Software Kings and queens\VB6 crack.exe
<Windows folder>\Software Kings and queens\Vietcong crack.exe
<Windows folder>\Software Kings and queens\Warcraft 3 crack.exe
<Windows folder>\Software Kings and queens\Windows media player Divx Codec.exe
<Windows folder>\Software Kings and queens\WinRAR 3.41 crack.exe
<Windows folder>\Software Kings and queens\Worms 3D crack.exe

and creates the following files:

<Program Files>\WinMX\library.dat
<Windows system folder>\skq\<number>.<random number>.sys

These two files are harmless and can be deleted.

W32/VBSilly-D will also attempt to overwrite files in the Windows system folder with the following extensions:

EXE
INI
OCX
TXT

The overwritten files are all copies of the worm.

The following registry entry is created to run skq.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SKQ
<Windows system folder>\skq\skq.exe

Registry entries are created under:

HKCU\Software\Kazaa\LocalContent\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer