Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | March 2008 (4.27) |
| Protection available since | 1 February 2008 18:50:49 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Hish-B is a worm for the Windows platform.
The worm patches the host file and attempts to terminate various Security related processes
W32/Hish-B includes functionality to access the internet and communicate with a remote server via HTTP.
When first run W32/Hish-B copies itself to:
<Startup>\Explorer.exe
<Root>\auto.exe
<Windows>\system.exe
and creates the following files:
<Root>\autorun.inf
<System>\upgrade.pdf
<Windows>\upgrade.tpl
The file autorun.if is detected as W32/SillyFD-G.
