|
Detection files published:
30 Jul 2001 |
Description created:
2001-12-11 |
Description updated:
2001-12-11 |
|
Alias:
|
Spreading mechanism
Network, Other | |
|
Payload:
| ||
This is a Visual Basic Script worm installed by another the W32/Updatr.C@mm worm.
This script will, when run, go through all directories on all accessible drives and create copies of itself. The copies will be named like already existing DOC, EXE, DLL or TXT files, with the exception that the files will have an extra VBS extension. F.ex. MyDocument.doc will be accompanied by a small script called MyDocument.doc.vbs. This script is a worm by itself, and does not spread or help the original worm that dropped it in any way.
On the 12th of any month the worm will show a small messagebox:
Hi there.., you are infected by some of
IWING creations.., Poly & crypt By. Iwing - have a nice day
Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.
| Usage | Title | Comment |
|---|---|---|
| Stopping network share infectors | ||
| Cleaning of back-up folders on Windows Me and XP |