Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Short description
Win32/VB.NSM is a worm that spreads by copying itself into certain folders.
Installation
When executed the worm copies itself in the following locations:
  • C:WINDOWSsystem32Dragon Son.exe
  • C:WINDOWSsystem32Play Boys.exe
  • C:WINDOWSsystem32PDA.exe
  • C:WINDOWSsystem32Shai Ling.exe
  • C:WINDOWSsystem32Internet V9.exe
In order to be executed on every system start, the worm sets the following Registry entry:
  • [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
    CurrentVersionRun]
    "Play Boys.exe" = "C:WINDOWSsystem32Play Boys.exe"
Other information
The worm may create the following folders:
  • %drive%Khmer MP3
  • %drive%Kong Fu Story
  • %drive%Phone Soft
  • %drive%Play Boy Sex
  • %drive%The Internet Last Version
The worm terminates any program that creates a window containing any of the following strings in its name:
  • Windows Task Manager
  • Run
  • Windows
  • Command Prompt