%PROGRAM FILES%\Sony\VAIO Action Setup\MsVBdll32.exe |
| Name |
%PROGRAM FILES%\Sony\VAIO Action Setup\MsVBdll32.exe |
Description
|
Worm W32.Aimdes.A@mm. MsVBdll spreads via e0mail and AOL Instant Messenger. Adds the value: "MsVBdll" = "%Windir%\MsVBdll.pif" to the Windows startup registry keys. Adds the registry entries: "FirewallDisableNotify" = "1" "UpdatesDisableNotify" = "1" "AntiVirusDisableNotify" = "1" to the following registry keys HKEY_CURRENT_USER\Software\Microsoft\security center HKEY_LOCAL_MACHINE\Software\Microsoft\security center to lower computer security. MsVBdll adds: "DisableTaskMgr" = "1" "DisableRegistryTools" = "1" to the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\System to disable access to the Windows Task Manager and registry editing tools. MsVBdll adds the registry entry: "NoAutoUpdate" = "1" to the registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU to disable Windows Update. MsVBdll deletes the following registry key if present: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\ CurrentVersion\Run\"Windows" = "Auto Update.exe" MsVBdll tries to copy itself to: A:\homework.exe Kills the system processes: * svchost.exe * lsass.exe It will break network connections. |
|
|
|
|