winsock.vbs - Dangerous

winsock.vbs

Manual removal instructions:

Antivirus Report of winsock.vbs:
winsock.vbs Malware
winsock.vbsDangerous
winsock.vbsHigh Risk
winsock.vbs
I-Worm.DragonBall
This Internet worm spreads via e-mail messages using MS Outlook and IRC, and is written in VBS.
The IRC scripts are needed for spreading via the IRC channel.

Then the worm activates a spread procedure, opening the MS Outlook address book, and for each address, creating the following message:
Subject: Hello ;]
Body: Hi , check out this game that j sent you (funny game from the net:]).
Attach: dragonball.vbs

The worm contains errors, and this procedure can't work correctly. So, the worm can't spreads via e-mail.
In conclusion, the worm displays the following dialogue box:
When a user closes this box, the worm removes keyboard and mouse functions, and the runs MediaPlayer with a file from the Internet:
http://bdball.metropoli2000.net/mmedia/v...
and changes AUTOEXEC.BAT, inserting the strings:
@ECHO ON
ECHO DraGon Ball [Z] by YuP
ECHO Thank you and bye bye dragon world!!

Please, remove it with RegRun.

Remove winsock.vbs now!

Dmitry Sokolov:

I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.

Since that time I work every day to fix the issues that antiviruses cannot.

If your antivirus have not helped you solve the problem, you should try UnHackMe.

We are a small company and you can ask me directly, if you have any questions.

Testimonials

You can read UnHackMe testimonials here.