| Name: | Fool |
| Aliases: | VBS/Fool.B, VBS/Fool.D, Mill.A, VBS.Mill.A, VBS.Mill.Worm,VBS/Millenium, VBS/Zipped.A , |
| Ports: | |
| Files: | MyPicture.bmp.vbs - Rundll.vbs - Millenium.nfo - Short.rsc -Short.com - Lcoder.exe - Lcoder.hex - Fix.hex - - 2,255 bytes (E) -2,555 bytes (D) - 5,989 bytes (F) |
| Created: | 1999 |
| Requires: | |
| Actions: | Remote Access / Worm / Trojan dropper / IRC trojan |
| Alters System.ini. Uses Windows Startup Directory to autostart. When using IRC the trojan opens the channel #xmasday and sends information about the host computer. On December 31, the trojan is among lots of other things also dropps the Remote Access trojan The Thing 1.6. | |
| Versions: | A, B, C, D, E, F, |
| Registers: | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\ |
| Notes: | Works on Windows, together with MS Outlook and mIRC. |
| Country: | |
| Program: | Written in Visual Basic Script (VBS). |