ietf
[Top] [All Lists]

RE: VIRUS WARNING

2000-05-04 07:40:02
The file subject: ILOVEYOU
Name of attachment: LOVE-LETTER-FOR-YOU.TXT.vbs

DO NOT OPEN THE ATTACHMENT.

At this time very little is known about the virus. If you have opened the
file, please see your network administrator for help.

The following link to Symantec has info on what the file does to your
system.

http://www.symantec.com/avcenter/venc/data/vbs.loveletter.a.html



Since the webpage is too busy to access I am copying the text portions of
the webpage here

VBS.LoveLetter.A
This is an email worm, mIRC worm, and file infector.

Also known as:

Category: Worm

Infection length: 10307

Virus definitions: Pending

Threat assessment:


Damage:
High
Distribution:
High
Wildness:
High


Wild

Number of infections: More than 1000
Number of sites: More than 10
Geographic distribution: High
Threat containment: Moderate
Removal: Moderate


Damage Payload:

Large scale e-mailing: All the addresses in Microsoft Outlook address book
Degrades performance: May clog mail servers
Distribution

Subject of e-mail: ILOVEYOU
Name of attachment: LOVE-LETTER-FOR-YOU.TXT.vbs
Size of attachment: 10307
Technical description:

This is a preliminary writeup. The information contained within is to
provide as much information as possible at this time.

VBS.LoveLetter.A is an email worm, mIRC worm, and a file infector.
VBS.LoveLetter.A will use Microsoft Outlook and email itself out as an
attachment with the above subject line and attachment name. The body of the
message will be

kindly check the attached LOVELETTER coming from me.

The virus will also infect files with the following extensions: vbs, vbe,
js, jse, css, wsh, sct, hta, jpg, jpeg, mp3, and mp2

The virus will insert the following files:

MSKernel32.vbs in the Windows System directory


Win32DLL.vbs in the Windows directory

LOVE-LETTER-FOR-YOU.TXT.vbs in the Windows System directory

WinFAT32.EXE in the Internet download directory

WIN-BUGSFIX.EXE in the Internet download directory

script.ini in the mIRC directory

SARC recommends Administrators filter on the attachment name and Subject
line immediately.

This writeup will be verified and formalized within the hour.

Removal:

Delete found infected files.



Write-up by: Eric Chien
Updated: May 4, 2000
  Tell a Friend about this Write-Up






-----Original Message-----
From: Scot Mc Pherson [mailto:smcpherson(_at_)clearaccess(_dot_)net]
Sent: Thursday, May 04, 2000 9:27 AM
To: isp-wireless(_at_)isp-wireless(_dot_)com; ietf(_at_)ietf(_dot_)org
Subject: VIRUS WARNING


The is an e-mail virus going around. The subject of the e-mail is
ILOVEYOU...I suggest you delete it the moment you receive it.

-Scot Mc Pherson, N2UPA
-Sr. Network Analyst
-ClearAccess Communications
-Ph: 941.744.5757 ext. 210
-Fax: 941.744.0629
-mailto:smcpherson(_at_)clearaccess(_dot_)net
-http://www.clearaccess.net



<Prev in Thread] Current Thread [Next in Thread>