This Visual Basic script (VBScript) may be dropped by other malware. It may also be downloaded unknowingly by a user when visiting malicious Web sites.
Upon execution, this VBScript drops a copy of itself. This VBScript creates a registry entry to enable its automatic execution at every system startup. This VBScript also modifies registry entry to hide files with both
System and
Read-only attributes.
This VBScript drops copies of itself in all removable drives. It also drops an
AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed.
This VBScript connects to a URL. As of this writing, however, the said URL is inaccessible.
More...