|
|
VBS.Netlo Viruses Information
| Name: |
VBS.Netlo |
| Category: |
Viruses |
| Description:
|
Details
VBS.Netlog
This is a worm written in Visual Basic Script language (VBS). It spreads through a network by coping itself to other computers in the network.
Upon being activated, the worm generates a random network IP address (for example 145.65.28.0), and tries to connect to all computers in this network. It changes the last octet of an address from 1 to 255 and tries to connect. If the connection is accepted, the worm copies itself to a connected computer on drive C: in the following folders:
C:C:WINDOWSSTARTM~1PROGRAMSSTARTUP
C:WINDOWS
C:WINDOWSSTART MENUPROGRAMSSTARTUP
C:WIN95START MENUPROGRAMSSTARTUP
C:WIN95STARTM~1PROGRAMSSTARTUP
C:WIND95
If all computers in this network are inaccessible, the worm generates a new network IP address.
The worm creates a file "C:NETWORK.LOG". In this file, the worm writes all of its activities. The file content appears as follows:
Log file Open
Subnet : 145.65.28.0
Subnet : 23.44.93.0
Subnet : 50.112.201.0
Subnet : 176.3.138.0
Copying files to : \176.3.138.5Ñ
Successfull copy to : \176.3.138.5Ñ
The spreading ability of this worm is very low, because search of a victim computer takes a lot of time and most computers reject a requested connection. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Jindra.204
Saturday1
Tutan.103
I-Worm.Mydoom.
Demiurg.306
Como.178
Mr_Gu Famil
GoodThursda
Dos.184.
Backdoor.Agobot.ge
|
|