Main Menu
Home
Bookmark
Contact Us



 
VBS.Mcon. Viruses Information

Name: VBS.Mcon.
Category: Viruses
Description: Details
VBS.Mcon.b

This worm spreads via networks, scanning them for accessible IP addresses and copies itself to them.
Being activated, the worm copies itself into the Windows fonts directory using the name "ttfload.vbs", and modifies the system registry to execute this file upon each Windows start-up. If a file has been activated from a folder other than "Fonts" or "Startup," the worm displays a false system-error message:
ERROR
FILE I/O ERROR
If the worm has been activated from a "Fonts" folder (upon Windows start-up), it runs a spreading routine.
This routine scans local hard drives and network disks. In each folder, it creates a copy of the worm's file. The created-file name the worm generates is as follows: it obtains a random file name from the recent file list, appends to its name to more than a hundred spaces and then appends the extension ".vbs". Thus, the true file extension ".vbs" is hidden with a large number of spaces.
After disk scanning is finished, the worm begins scanning the network for accessible IP addresses. It checks randomly generated IP addresses, and if the address is accessible, it tries to copy itself there.
If the worm finds the directory-contained string "mirc" in the name, it creates a SCRIPT.INI file in there. The script program in this file is automatically executed upon MIRC start-up. This script scans the network in the same way as the worm does. If an accessible IP address is found, it sends a worm copy to that address.
Depending on a randomly generated number in one case in a thousand, the worm replaces a browser's start page to "http://www.zonelabs.com/".



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Hiroshima.82
Perfume Famil
Axe.88
SadFace.84
XIV.224
Fasolo.14
LZ
Futhark.96
Oulu.100
Fist.92


 


© 2006-2008 spyware32.com - Privacy Policy