VBS Stages.A Virus
How to Detect it and Remove It
the VBS.Stages worm?
How Does the Worm Activate?
When someone opens the LIFE_STAGES.TXT.SHS file, it opens notepad and displays the following joke about the different stages of life for females and males.
While the user is reading this joke, the worm installs itself into the infected computer. It creates the following registry entry, so that is runs at Windows startup.
It drop the scanreg.vbs file into the c:\windows\system directory and creates registry entries to activate when ICQ is loaded. To spread via IRC channels, it creates the file SOUND32B.DLL called by MIRC. This allows the worm to spread via IRC channels, as well as email.
It also sends the virus via email to all addresses in the infected computer's address book.
Finally, it deletes the file REGEDIT.EXE and moves it to the Recycle Bin with the name RECYCLED.VXD. This makes it hard to remove the worm because you can't edit the windows registry.
VBS.Stages.A also creates files with random names in the system and all available drives using the following fixed names:
random names generated are the following:
creation of the random named SHS files, the virus uses the following
algorithm to determine a name:
a selection of one of five choices:
How to Clean/Delete the VBS.Stages worm
You must locate a copy of the REGEDIT.EXE file from the original Windows disks or another computer to be able to edit the windows registry and remove the worm. You may also download the file FIXSTAGE.EXE from the Trend Micro website to correct the registry ad remove the files dropped by the worm. This will not delete the actual virus but it will correct most of the damage done to the system.
The actual virus can be deleted by searching your system for file scanreg.vbs or quite frankly any other .vbs file type, and deleting it. VBS files are Visual Basic Scripts that may contain viruses.
Also visit my page on how to protect yourself from these email viruses
|Recommended Software for PC Hell Visitors|
iolo System Mechanic®
Emsisoft Anti Malware