VBS.Netlog
Description VBS.Netlog
This is a worm written in Visual Basic Script language (VBS). It spreads through a network by coping itself to other computers in the network. Upon being activated, the worm generates a random network IP address (for example 145.65.28.0), and tries to connect to all computers in this network. It changes the last octet of an address from 1 to 255 and tries to connect. If the connection is accepted, the worm copies itself to a connected computer on drive C: in the following folders: C:C:WINDOWSSTARTM~1PROGRAMSSTARTUP C:WINDOWS C:WINDOWSSTART MENUPROGRAMSSTARTUP C:WIN95START MENUPROGRAMSSTARTUP C:WIN95STARTM~1PROGRAMSSTARTUP C:WIND95 If all computers in this network are inaccessible, the worm generates a new network IP address. The worm creates a file "C:NETWORK.LOG". In this file, the worm writes all of its activities. The file content appears as follows: Log file Open Subnet : 145.65.28.0 Subnet : 23.44.93.0 Subnet : 50.112.201.0 Subnet : 176.3.138.0 Copying files to : \176.3.138.5Ñ Successfull copy to : \176.3.138.5Ñ The spreading ability of this worm is very low, because search of a victim computer takes a lot of time and most computers reject a requested connection.
Check other viruses! Be aware! Use Antiviral Software
MG.a
Description MG.a
These are harmless memory resident parasitic viruses. They hook INT 13h, 21h. When DOS functions 36h,39h,47h,4Bh are executed, the viruses search for .COM files and write themselves to the end of the file.
Mgn.2048.a
Description Mgn.2048.a
These are harmless memory resident encrypted parasitic viruses. They were received from Magnitogorsk city (Russia). The viruses hook INT 8, 13h, 21h and write themselves to the end of COM and EXE files that are executed or closed, the COMMAND.COM file is infected by the algorithm of the "Lehigh" virus. The viruses disinfect the infected files that are opened, they also do not infect the files when the Num-Ins-Ctrl keys are pressed at the same time. Therefore the simplest way to cure a computer infected by such viruses is to process by any anti-virus program all COM and EXE files in all directories on all disks having Num-Ins-Ctrl pressed, and then to reboot the computer. The viruses contain the string "COMMAND". "Mgn.2560.c" replaces the 50h disk type with the 51h in the Partition Table (these disk types are used by Disk Manager utility). "Mgn.2048" hourly "overturn" the screen. "Mgn.2048.b" contains the text: Shadow & Safe
"Mgn.2560.a,b,c" periodically display: +--------------------------------------+ ƒ Mr. Lozinsky ! ƒ ƒ Just read documentation on your ƒ ƒ AIDSTEST (1-Oct-90 version) we ƒ ƒ release new virus. Create improved ƒ ƒ versions of AIDSTEST, please ! ƒ ƒ(C) TinySoft&Electronics,Inc. 3-Nov-90ƒ +--------------------------------------+
"Mgn.3000" sets the screen colors to white/blue/red (the colors of Russian national flag).
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Door Systems Laptop Rental Hvordan Tjene Penger På Hjemmesiden Domene Lenkebygging
|