|
|
VBScript.77 Viruses Information
| Name: |
VBScript.77 |
| Category: |
Viruses |
| Description:
|
Details
VBScript.777
This is a very dangerous parasitic virus written in Windows Script language. When an infected script takes control, the virus searches for other scripts (.VBS files) and infects them in the current and Windows directories, then in the Windows directories:
ProfilesAll UsersDesktop
ProfilesAdministratorDesktop
Desktop
While infecting the virus shifts files down and writes its code to the beginning of the file. As a result the original contents of affected files is not damages. The virus detects already infected scripts by the "'VBSv777" identification string that is placed at the top of virus code.
On 2nd of each month from 9:00 till 10:00 if the virus is activated, it searches for all .DOC and .TXT files on the C: and D: drives and overwrites them with the picture:
_ _
|_| |_|
| | /^^^ | |
_| |_ (| %o% |) _| |_
| | | | _ (_---_) _ | | | |_
| | | | |' | _| |_ | `| | | | |
| | / | |
/ / /(. .) /
/ / / | . | /
/ / ||Y|| / /
__/ || || __/
() ()
|| ||
ooO Ooo
Greetings From CTRL-ALT-DEL /CB + AVM
- http://www.codebreakers.org -
The virus then displays the MessageBox:
Greetings From CTRL-ALT-DEL /CB + AVM
- http://www.codebreakers.org - |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
YanShort.Bandi
Macro.Word97.Unhel
Macro.Word.Gavi
Macro.Word97.DasWo
Abola.242
BadBoy.1000.
MLTI.830.
Mini_HHHH.24
Trakia.56
Face.252
|
|