VBS.Biscuit.B is a variant of
VBS.Biscuit.A@mm, which can spread by network shares.
The worm attempts to copy itself to both the local host and reachable remote network shares. It will copy itself to the root of the network share as Netlog.vbs.
The worm will also copy the original worm's filename to the following folders, if it is able to copy Netlog.vbs to the root of the share:
- <network share root>\Windows\Menu Avvio\Programmi\Esecuzione automatica
- <network share root>\Windows\startm~1\programs\startup
- <network share root>\Windows
- <network share root>\Windows\start menu\programs\startup
- <network share root>\Win95\start menu\programs\startup\
On the 10th of every month, VBS.Biscuit.B displays a pop-up message.
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.