Worm.VBS.Netlog.l
This worm is 2282 bytes in size. It is written in Visual Basic Script (VBS). It spreads by copying itself to other computers on the local network .
Once the worm is launched, it selects a rendom network IP address where the first octect is equal to 65 e.g. 65.24.52.0. It will then attempt to connect to all computers on this network, cycling through 1 to 255 for the final octet of the IP address. If the worm is able to establish a connection, a shared network disk x: will be created on the infected machines. The worm then copies the following files: c:\windows\startm~1\programs\startup\_chubby.vbs c:\sys32.exe to the startup directory on the networked disk: x:\windows\startm~1\programs\startup It also copies c:\sys32.exe to the x: root directory. The network disk will then be disabled.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
|
||||||||