Home / malwarePDF  

Worm.VBS.Solow.A


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Worm.VBS.Solow.A is also known as Worm.VBS.Slogod.

Explanation :

Once executed, the worm replicated copying itself in %WINDIR% directory and in root directories of all fixed and removable disk drives except A: drive. After that it creates autorun.inf on all fixed and removable drives except A: drive and sets the worm to be executed at disk autorun.

Also the worm sets Main Window Title of Internet Explorer to: "Hacked by Godzilla", and executes explorer.exe with infected filename argument, thus executing itself in an infinite cycle, this way every time you intoroduce a new removable drive, it infects it.

Last update 21 November 2011

 

TOP