Even more destructive virus alert !
Posted on 19/05/00 14:02 by Jan Willem                             
Even more destructive virus alert !
Submitted by: Administr8or
Source: http://www.symantec.com

VBS.NewLove.A

SARC, in conjunction with other anti-virus vendors, has renamed this worm from VBS.LoveLetter.FW.A to VBS.NewLove.A.

The VBS.NewLove.A is a worm, and spreads by sending itself to all adressees in the Outlook address book when it is activated. The attachment name is randomly chosen, but will always have a .Vbs extension. The subject header will begin with "FW: " and will include the name of the randomly chosen attachment (excluding the .VBS extension) Upon each infection, the worm introduces up to 10 new lines of randomly generated comments in order to prevent detection.

Technical Description:

This polymorphic Loveletter variant will overwrite ALL files that are not currently in use regardless of extension. It arrives as an email message with a subject of "FW: FILENAME.EXT" and an attachment named "FILENAME.EXT.VBS" (where FILENAME.EXT is derived from the infected user's recently opened documents list.) The body of the email is empty. If no documents have been used recently, this name is randomly generated. If the message has been generated by a system running Windows NT or Windows 2000, then the filename will be omitted and the subject of the message will be "FW: .EXT" and the attachment name will be ".EXT.VBS" (again, the file extension will vary depending on the recently opened documents list of infected machines.)

Removal:

The contents of all files will be deleted, leaving the affected files with a byte length of zero. The worm will also append the extension '.vbs' to each of these files. For example, the file calc.exe will become calc.exe.vbs. Since this worm overwrites all files regardless of extension, proper removal can only be achieved by restoring the affected files from known clean backups.

More info: Symantec

---------------
They get better and better
Reactions
Discuss this article with your fellow community members! We appreciate your valuable input, but please keep the reaction policy in mind and make sure your reaction is constructive.
By Unknown, Fri 19 May 2000 22:22
Hmmm... It seems 2 b a good way of freeing up hard disk space...
By Unknown, Sat 20 May 2000 04:49
Oooops, sorry.......
By Unknown, Tue 23 May 2000 00:02
Strange, when i was scanning my computer for virusses, it found newlove, a htm file in the temperary internet files was infected. It was a site that explained how the "i love you" virus works.

Norton deleted the file, and everything on my computer is working. STRANGE.

TheScape

Name: Email:



Your comment:

Receive notification on new comments?