Author Topic: VBS:Agent-BCH  (Read 1221 times)

0 Members and 1 Guest are viewing this topic.

Offline Peter_in_Sweden

  • Newbie
  • *
  • Posts: 6
VBS:Agent-BCH
« on: February 24, 2023, 11:15:05 AM »
Yesterday, AVAST removed the malicious code, but in any case, I wonder what other people's experience is with all the code being gone. Have read here on the forum that it does not always succeed.
Ciao from Sweden

This is the message I got:
Everything is gone!
We've removed all the harmful stuff, so now you can blow off steam.
VBS:Agent-BCH

Everything is gone!
We've removed all the harmful stuff, so now you can blow off steam.
VBS:Agent-BCH


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: VBS:Agent-BCH
« Reply #1 on: February 24, 2023, 01:00:35 PM »
The script is embedded into HTML websites and designed to exploit a vulnerability described here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003

Damage:
Stolen banking information, passwords, identity theft, victim's computer added to a botnet.

Infested webpages, fake software are often ways for cybercriminals to infest with VBS:Agent-BCH.
Always be careful with opening suspicious mails, never use so-called cracking-tools, fake software etc.

Be aware now to not being re-infested.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Peter_in_Sweden

  • Newbie
  • *
  • Posts: 6
Re: VBS:Agent-BCH
« Reply #2 on: February 24, 2023, 07:20:21 PM »
Thanks for feedback on this issue Polonus!
I think its time for me to do an startup full scan
 Scan for threats before Windows starts.
Ciao!
Peter