oxney.vbs - Dangerous
oxney.vbs
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The email has the following characteristics:
Subject: Fw: give some ...
Attachment: Variable file name.
This worm also adds comments to .vbs, .vbe, .htm, and .html files in the root folder of the C drive.
Creates a copy of itself as %System%\Oxney.vbs and sets the System attribute.
Adds the value: "SPINX" = "Oxney.vbs"
to the registry key: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
Adds the value: "SPINX" = "why you'r still drunk ???"
to the registry key: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion
Adds the following comment to all the .vbs and .vbe files that it finds in the root of the C drive.
'I'm sorry friend, I have no money !!
Adds other comments to all the .htm and .html files that it finds in the root of the C drive.
Automatic removal:
Use RegRun Startup Optimizer.