Fool


Name: Fool
Aliases: VBS/Fool.B, VBS/Fool.D, Mill.A, VBS.Mill.A, VBS.Mill.Worm,VBS/Millenium, VBS/Zipped.A ,
Ports:
Files: MyPicture.bmp.vbs - Rundll.vbs - Millenium.nfo - Short.rsc -Short.com - Lcoder.exe - Lcoder.hex - Fix.hex - - 2,255 bytes (E) -2,555 bytes (D) - 5,989 bytes (F)
Created: 1999
Requires:
Actions: Remote Access / Worm / Trojan dropper / IRC trojan
Alters System.ini. Uses Windows Startup Directory to autostart. When using IRC the trojan opens the channel #xmasday and sends information about the host computer. On December 31, the trojan is among lots of other things also dropps the Remote Access trojan The Thing 1.6.
Versions: A, B, C, D, E, F,
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
Notes: Works on Windows, together with MS Outlook and mIRC.
Country:
Program: Written in Visual Basic Script (VBS).

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>