d.com

the d.com i think is another modified vbs:autorun
when you set your hidden file to show, it sets it back to hidden,
but it doesnt’ remove the folder option…
it sets the value of the superhidden key to 3 in the registry…

and heres’ the autorun.inf file that comes with it

;oa4rwK38k4ao5idSKoj3cj3j6lao0407ssS3oqjka4dkpfasAq9defXK53ak7asf59k4aA2lDD82diai9q1sr5l2AZkAw0o3nLk
[AutoRun]
;kodSq7kp40DrlDk854Aa0q6Sso7aw
open=d.com
;Owi10l2koJ3Za7JKwIk9DasA8sFknAkw33qr3Kik4o
shell\open\Command=d.com
;Ks042Xw2KOo1LqHd0JllidrwKifsDalI4k4frL9kSsA0D3s8dL0s28iLmkww2eA
shell\open\Default=1
;ScXD3Kn3qdKla53a
shell\explore\Command=d.com
;3ldKXskKlar2ks2sipwKwLA0ilq44D37kw0kD3Lrir22f12ds9qKo0kLr8daSJsDqdrasAalfjrd4Caolwk1rDLljZi7aZrwAswdKwDid570JIlFi2ie1SOAo3q5o

this virus(?) spread itself thru mmc, mp3/mp4 players, flashdisk, ipod, and all those removable drive and external hard drive as well…

d.com is now identified / recognized by avast… just update your avast antivirus to remove this virus…

Good, improved speed of adding samples :wink:

yep thanx to avast and avast team…
more power to you and your team.