Content

VBS/Count

Type
Virus
SubType
mIRC Worm
Discovery Date
12/18/2000
Length
4,104
Minimum DAT
4114 (01/03/2001)
Updated DAT
4114 (01/03/2001)
Minimum Engine
5.1.00
Description Added
12/20/2000
Description Modified
09/18/2002 11:27 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

The Windows Scripting Host (part of Internet Explorer 5) is required for this virus to function.

When this Visual Basic Script virus is executed, it will modify the "C:\MIRC\SCRIPT.INI" file to instruct mIRC to distribute the worm to others when connecting to a chat room. However, the file specified,

"CounterstrikeRP.TXT                                       .vbs"
(in the "C:\WINDOWS\SYSTEM" directory)
is not created by the actions of this worm and therefore this action will fail. When an infected user quits the mIRC program, a message is displayed:
%Channel% "a|ien rules the base, RP ownz them! ;-)"

Symptoms

Presence of the files mentioned in this description.

Method of Infection

Accidentally or intentionally running this script infects your machine.

The worm copies itself to "c:\WINDOWS\system\RP.TXT.vbs", and "c:\WINDOWS\Start Menu\Programs\StartUp\Startup§.vbs"

If the day of the month is 1,5,10,15,20, or 25 the script creates a bitmap image. This is accomplished by creating the files, "C:\WINDOWS\RP.DLL", and "C:\WINDOWS\WINSTART.BAT". The batch file is used to convert the RP.DLL file to RP.BMP. The Wallpaper is then set to "C:\WINDOWS\CounterstrikeRP.BMP", which does not exist.

Removal

-

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • VBS.Sheep
  • VBS/Sheep-A
  • VBS/Sheep.a
  • VBS_SHEEP.A

Characteristics

Characteristics -

The Windows Scripting Host (part of Internet Explorer 5) is required for this virus to function.

When this Visual Basic Script virus is executed, it will modify the "C:\MIRC\SCRIPT.INI" file to instruct mIRC to distribute the worm to others when connecting to a chat room. However, the file specified,

"CounterstrikeRP.TXT                                       .vbs"
(in the "C:\WINDOWS\SYSTEM" directory)
is not created by the actions of this worm and therefore this action will fail. When an infected user quits the mIRC program, a message is displayed:
%Channel% "a|ien rules the base, RP ownz them! ;-)"

Symptoms

Symptoms -

Presence of the files mentioned in this description.

Method of Infection

Method of Infection -

Accidentally or intentionally running this script infects your machine.

The worm copies itself to "c:\WINDOWS\system\RP.TXT.vbs", and "c:\WINDOWS\Start Menu\Programs\StartUp\Startup§.vbs"

If the day of the month is 1,5,10,15,20, or 25 the script creates a bitmap image. This is accomplished by creating the files, "C:\WINDOWS\RP.DLL", and "C:\WINDOWS\WINSTART.BAT". The batch file is used to convert the RP.DLL file to RP.BMP. The Wallpaper is then set to "C:\WINDOWS\CounterstrikeRP.BMP", which does not exist.

Removal -

Removal -

-

Variants

Variants -

    N/A