VBS/CoolNot@mm

Download VIRUSfighter NOW
VBS/CoolNot@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 10/16/2000 • Type: Worm
• Virus characteristics first published: 10/16/2000 • Spreading mechanism: Email, IRC
• Virus characteristics latest update: 12/17/2003 • Overall risk: Low
• Infection type: Microsoft Visual Basic Script  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: Cool Notepad Demo
  • Body: Hey check out this text file I sent it will do something neat in notepad. Enjoy :-)
  • Attachment: COOL_NOTEPAD_DEMO.TXT.vbs
This worm copies itself to the Windows' system folder as COOL_NOTEPAD_DEMO.TXT.vbs and modify the Registry to execute this file each time Windows is started. Then it modifies Registry to hide the Desktop after Windows is restarted.

After this the worm performs a check to see if mIRC is installed at the infected system. If mIRC is installed, the worm will overwrite mirc.ini if mIRC is installed to c:\mirc. The new mirc.ini will send the infected file, COOL_NOTEPAD_DEMO.TXT.vbs, to all users who join the same channel as the infected user, and also send a short message to the #virus channel. The message is: "Cool Notepad Demo".

The worm uses MS Outlook to send itself to all entries in all address books.
# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter