Proactive IT Security
 

VBS/Updatr.C

Threat risk

Threat risk none

Detection files published:
30 Jul 2001
Description created:
2001-12-11
Description updated:
2001-12-11

Malware type:
Worm
Alias:
Spreading mechanism
Network, Other

Payload:

Summary

This is a Visual Basic Script worm installed by another the W32/Updatr.C@mm worm.
 

Spreading description

This script will, when run, go through all directories on all accessible drives and create copies of itself. The copies will be named like already existing DOC, EXE, DLL or TXT files, with the exception that the files will have an extra VBS extension. F.ex. MyDocument.doc will be accompanied by a small script called MyDocument.doc.vbs. This script is a worm by itself, and does not spread or help the original worm that dropped it in any way.
 

Threat description

On the 12th of any month the worm will show a small messagebox:

Hi there.., you are infected by some of
IWING creations.., Poly & crypt By. Iwing - have a nice day

 

Removal

General information about removal of malicious software

Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.

Usage Title Comment
  Stopping network share infectors  
  Cleaning of back-up folders on Windows Me and XP