Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Virus Warning

  • 04-05-2000 11:02pm
    #1
    Registered Users, Registered Users 2 Posts: 1,641 ✭✭✭


    Attachment "i love you" is a new virus like Melissa only smarter. Details are sketchy but its already got most big companies incl. MS.


Comments

  • Registered Users, Registered Users 2 Posts: 3,744 ✭✭✭deRanged


    it arrived in my company this morning from south africa.
    it's a vb script one.
    mails itself to everyone in your address book and tries to send itself using your chat clients as well. it also does something to your IE reg settings.
    good thing I use linux smile.gif


  • Registered Users, Registered Users 2 Posts: 10,339 ✭✭✭✭LoLth


    anywhere "official" to get info on this?

    Our company was hit this morning as well, and the email server was pulled offline as a safety precaution.


  • Moderators, Social & Fun Moderators Posts: 28,633 Mod ✭✭✭✭Shiminay


    We got hit with a similar one a few weeks back - it was called "Check out these Links" or something like that.

    These are dangerous times we're living in!!!



    All the best,

    Dav
    @B^)
    My page of stuff


  • Registered Users, Registered Users 2 Posts: 16,414 ✭✭✭✭Trojan


    Hey guys,

    There's a virus going round at the moment, it managed to take down our network for a while today.

    The title of the email is "I LOVE YOU". It is not ActiveX based within the email itself, but contains a VB script attachment.

    I've had a quick look at the source - nasty piece of work. It's a VBS file called "LOVE-LETTER-FOR-YOU.txt.vbs" - how subtle with the extensions... smile.gif

    It does some stuff like messing with the registry, reading through your directories & writing stuff into your files, it d/ls an exe from the web - remove ".BREAKLINK" to enable this, its just you don't hit it by accident smile.gif
    http://www.skyinet.BREAKLINK.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf7679njbvYT/WIN-BUGSFIX.exe

    Anyways that's the craic, be careful with this.

    Al.

    Addendum: It also searchs for misc, tries to propogate itself with this too..



  • Registered Users, Registered Users 2 Posts: 10,339 ✭✭✭✭LoLth


    well, this is what I found.

    VBS.LoveLetter.A
    This is an email worm, mIRC worm, and file infector.

    Also known as:

    Category: Worm

    Infection length: 10307

    Virus definitions: Pending

    Threat assessment:


    Damage:
    High Distribution:
    High Wildness:
    High


    Wild

    Number of infections: More than 1000
    Number of sites: More than 10
    Geographic distribution: High
    Threat containment: Moderate
    Removal: Moderate
    Damage

    Payload:

    Large scale e-mailing: All the addresses in Microsoft Outlook address book
    Degrades performance: May clog mail servers
    Distribution

    Subject of e-mail: ILOVEYOU
    Name of attachment: LOVE-LETTER-FOR-YOU.TXT.vbs
    Size of attachment: 10307
    Technical description:

    This is a preliminary writeup. The information contained within is to provide as much information as possible at this time.

    VBS.LoveLetter.A is an email worm, mIRC worm, and a file infector. VBS.LoveLetter.A will use Microsoft Outlook and email itself out as an attachment with the above subject line and attachment name. The body of the message will be

    kindly check the attached LOVELETTER coming from me.

    The virus will also infect files with the following extensions: vbs, vbe, js, jse, css, wsh, sct, hta, jpg, jpeg, mp3, and mp2

    The virus will drop the following files:

    MSKernel32.vbs in the Windows System directory
    Win32DLL.vbs in the Windows directory
    LOVE-LETTER-FOR-YOU.TXT.vbs in the Windows System directory
    WinFAT32.EXE in the Internet download directory
    WIN-BUGSFIX.EXE in the Internet download directory
    script.ini in the mIRC directory


    SARC recommends Administrators filter on the attachment name and Subject line immediately.

    This writeup will be verified and formalized within the hour.

    Removal:

    Delete found infected files.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 10,339 ✭✭✭✭LoLth


    wheeee,
    www.sophos.com have just updated and have an ide file for taking care of it.

    Symantec heven't updated yet so norton peeps will have to wait.


Advertisement