Home Malware Programs Viruses Virus.Win32.VB.cz

Virus.Win32.VB.cz

Posted: September 21, 2011

Threat Metric

Ranking: 1,487
Threat Level: 1/10
Infected PCs: 44,563
First Seen: September 21, 2011
Last Seen: October 17, 2023
OS(es) Affected: Windows

Virus.Win32.VB.cz is a dangerous computer virus which spreads by sharing itself over a network or computer file that involves a malicious file. Virus.Win32.VB.cz may modify the registry and control your PC activities. Virus.Win32.VB.cz shows annoying pop-up security alerts on the infected computer. Virus.Win32.VB.cz can download and install additional malware infections. Virus.Win32.VB.cz invades your privacy and compromises your security. Virus.Win32.VB.cz should be removed as early as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



setup[RANDOM CHARACTERS]0000.exe File name: setup[RANDOM CHARACTERS]0000.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%PROGRAM_FILES%\ Virus.Win32.VB.cz \ Virus.Win32.VB.cz File name: %PROGRAM_FILES%\ Virus.Win32.VB.cz \ Virus.Win32.VB.cz
Mime Type: unknown/cz
Group: Malware file
%Documents and Settings%\All Users\Application Data iosejgfse.dll File name: %Documents and Settings%\All Users\Application Data iosejgfse.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System 'DisableTaskMgr' = '1'KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments 'SaveZoneInformation' = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyOverride' = "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download 'RunInvalidSignatures' ='1'HKEY_LOCAL_MACHINE\Software\ Virus.Win32.VB.czHKEY_LOCAL_MACHINE\SOFTWARE\Paladin AntivirusHKEY_CURRENT_USER\Software\Paladin AntivirusHKEY_CURRENT_USER\Software\Malware Defense

Additional Information

The following URL's were detected:
fileconversionnow.com
Loading...