Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


VBSWG.V@mm


Aliases:


VBSWG.V@mm

Malware
Worm
VBS

Summary

This variant spreads in messages with following content:

  Subject:    Check out this preteen pic!!
    Body:       Hey here is a great preteen pic. She is 12 years old totally bald..
    Attachment: Cindy12yr.vbs




Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

When the attached file is executed, the worm will mail itself to the each recipient in every address book. After mass mailing the following key is added to the registry:

  HKEY_CURRENT_USER\software\Cindy\mailed


This variant also replicates using mIRC and Pirch IRC clients. It replaces the "script.ini" from mIRC and "events.ini" from Pirch installation directories, causing that the worm will send itself to the IRC user that joins the channel where an infected user is.

VBSWG.V also goes trough all local and network drivers from the system, and replaces every file with either ".vbs" or ".vbe" extension with itself. It also attempts to locate mIRC and Pirch installations from these drives.

This variant shows the following message box upon execution:

  Error Decompressing JPEG Picture


Information about the original VBS/Onthefly.A (also known as I-Worm.Lee.o and VBS/VBSWG) is available at: http://www.F-Secure.com/v-descs/onthefly.shtml





Description Created: Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure; March 2001



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free