|
The LoveLetter Worm and
Its Variants
I Love You
Aliases:
The Love Bug
VBS/LoveLet-A
LOVE-LETTER-FOR-YOU.TXT
VBS/Loveletter
|
The LoveLetter Worm and Its Variants The original LoveLetter worm This worm, which infects Windows systems, is a worm that spread over the Internet yesterday, and is no doubt spreading today. The message looked like this: Subject: ILOVEYOU
The message may supposedly be from a friend or someone you know, but it was in fact the worm sending you a message using the Microsoft Outlook address book of an infected computer. It can also send itself via mIRC. After connecting to a chat server using mIRC, the virus initiates a DCC send to all the users in the current channel and sends a copy of itself, LOVE-LETTER-FOR-YOU.HTM. If you receive this email message or the HTM file, DO NOT OPEN THE ATTACHMENT OR THE FILE
The new variants and mutations There are three new variations on the original LoveLetter virus that have been discovered so far. Again, as stated above, if you receive one of these variants, DO NOT OPEN THE ATTACHMENT OR THE FILE. Simply delete the email and inform the person the email was supposedly from that their computer is infected. Variant 1: Subject: Susitikim shi vakara kavos puodukui...
Variant 2: Subject: fwd: Joke
Variant 3(the Mother's Day variant):
Subject: Mothers Day Order Confirmation
NOTE: This variant also deletes all files with the extension ".ini" and ".bat" which makes it all the more dangerous.
The LoveLetter worm :
Once activated, the worm deletes files of these extensions:
It creates the following files:
The worm makes changes to the registry that loads the worm each time Windows is started. It creates the following entries:
If the Trojan horse is downloaded, and the file WIN-BUGSFIX.exe does not exist in the Windows system folder, then it will create the key:
You must delete these registry keys as part of the removal process, otherwise you will experience errors when Windows tries to load these files. In-depth Technical Details Removal of the Worm Automated Removal There are now some tools available that can help you to clean the virus from your system. These tools can help you accomplish the three steps to removing this virus: 1. Fixing the Registry Computer Associates has developed an executable program that will remove the registry changes made by the virus. It is available at:
Once you download the file, double-click on it to run the program and remove the registry keys. 2. Removing the Infected Files Trend Micro has a website that will scan for the infected files online (we have ourselves not verified that it will remove the infected files as of yet). Their virus-cleaning website is http://housecall.antivirus.com/ 3. Resetting your Internet Explorer home page The virus changes the home page for Internet Explorer so the next time you open up the browser, you will be taken to a web page where it is suspected that another virus or trojan program will be downloaded (if your IE has already visited this page, it may have transmitted your Windows passwords, so be sure to change them just to be safe). To fix this:
Once you have gone through all three of the above steps, you system should be clean. Step-by-Step Removal Instructions
The virus changes the home
page for Internet Explorer so the next time you open up the browser, you
will be taken to a web page where it is suspected that another virus or
trojan program will be downloaded (if your IE has already visited this
page, it may have transmitted your Windows passwords, so be sure to change
them just to be safe). To fix this, click on the Start button, choose Settings,
and choose Control Panel.
In the Current Version directory
list in the left column, click on directory labeled Run so that the Run
folder opens.
Hit the Delete key. When
asked if you want to delete this registry key, click on the Yes button.
The entry should then disappear.
Click the Find Now button
to start the search. The search results will be listed in the window below.
Click on the MSKernel32.vbs file once to highlight it (as shown above),
and then hit the Shift key and the Delete key simultaneously. When asked
if you want to really delete this file, click the Yes button.
Restart your computer. |
||||||||
|
[an error occurred while processing this directive] |
Howdy!!! Welcome to the McCann's PooR Farm I'm not with any school or schools, Just a disable grandpa with 17 grand kids, 1 Great grand Kid Sorry! about all of the adds, Our Cost just keeping going up. Please click on one of them and help us out. or Send $1.00 U.S. to: McCann's Poor Farm 20509 Lawrence 2207 Aurora, Mo. 65605-7275 Thank You, Junior McCann Webmaster and the GrandKids See what the experts have to say about the McCann's Poor Farm Web Page Legal Disclaimer - We Are in no way connected with any School and or Companies linked to this page. Links are provided as a courtesy only. |
Argentina, Australia, Austria, Belarus, Belgium, Bermuda, Brazil, Brunei Darussalam, Bulgaria, Canada, Chile, Columbia, Costa Rica, Croatia, Croatia/Hrvatska, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Korea, Korea, Republic of, Latvia, Lebanon, Lithuania, Luxembourg, Macedonia, Malaysia, Mexico, Moldova, Netherlands, New Calendonia, New Zealand, Norway, Old style Arpanet, Papua New Guinea, Peru, Philippines, Poland, Portugal, Romania, Russian Federation, Saudi Arabia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Turkey, Uganda, Ukraine, United Arab Emirates, United Kingdom, United States, Uruguay, USA Government, USA Military, Viet Nam |
Tell A Friend about this Page |
Tell me when this page is updated |
|
Put a Link on your Web Page
- Legal Disclaimer - |