> -----Original Message----- > From: AVG Virus Alert <[EMAIL PROTECTED]> > To: [EMAIL PROTECTED] <[EMAIL PROTECTED]> > Date: Tuesday, May 09, 2000 5:52 AM > Subject: AVG Virus Alert - New variants of VBS/Iloveyou > > > >= This message comes from AVG Virus Alert mailing list. You got it, > >= because you have subscribed this service or you are registered > >= user of AVG Anti-Virus System. If you don't want to get this > >= information, please see the bottom of this message. > > > >VBS/Iloveyou > >============ > > > >Here is a list of all known variants of the virus > >VBS/Iloveyou and one good message: > > > > http://www.zdnet.co.uk/news/2000/18/ns-15233.html > > > >Note that only differences to the previously described > >original variant VBS/Iloveyou.A are included below. > > > >VBS/Iloveyou.B > >-------------- > > > >A mail with virus contains: > > Subject: > > Susitikim shi vakara kavos puodukui... > > Body: > > kindly check the attached LOVELETTER coming from me. > > Attached file: > > Very Funny.vbs > > > >A file sent via mIRC is: > > LOVE-LETTER-FOR-YOU.HTM > > > > > >VBS/Iloveyou.C > >-------------- > > > >A mail with virus contains: > > Subject: > > fwd: Joke > > Body of mail is empty > > Attached file: > > Very Funny.vbs > > > >A file sent via mIRC is: > > Very Funny.HTM > > > > > >VBS/Iloveyou.D > >-------------- > > > >A mail with virus contains: > > Subject: > > How to protect yourself from the IL0VEY0U bug! > > Body: > > Here's the easy way to fix the love virus. > > Attached file: > > Virus-Protection-Instructions.vbs > > > >A file sent via mIRC is: > > Virus-Protection-Page.HTM > > > >At the beginning of the virus is one comment added : > > Barok writes fucked code. And he can't spell for crap, either > > > > > >VBS/Iloveyou.E > >-------------- > > > >A mail with virus contains: > > Subject: > > Important ! Read carefully !! > > Body: > > Check the attached IMPORTANT coming from me ! > > Attached file: > > Important.TXT.vbs > > > >A file sent via mIRC is: > > Important.HTM > > > >Files dropped in windows and system directories are: > > ESKernel32.vbs, ES32DLL.vbs > > > >Comment lines at the beginning of the virus are replaced with: > > rem brain -Important(vbe) <What da fuck ?!> > > rem by: BrainStorm / @ElectronicSouls > > > >Comments in the SCRIPT.INI file changed to: > > ;BrainStorm > > ;http://www.ElectronicSouls.8m.com > > > > > >VBS/Iloveyou.F > >-------------- > > > >A mail with virus contains: > > Subject: > > Yeah, Yeah another time to DEATH... > > Body: > > This is the Killer for VBS.LOVE-LETTER.WORM. > > Attached file: > > Vir-Killer.vbs > > > >Code for sending via mIRC is removed. > > > >Comment lines at the the beginning of the virus are replaced with: > > rem Und noch so ein haessliches Ding > > rem Construction with The Original Letter.A Vir > > rem by Lucky2000 > > rem > > rem Hello all,,,Yes our PC are Infected... > > > >Start page in Explorer is randomly set to one of this values: > > http://www.yahoo.com/Vir-Killer.exe > > http://www.msn.com/Vir-Killer.exe > > http://www.Hotmail.com/Vir-Killer.exe > > http://www.Aol.com/Vir-Killer.exe > > > >Changes in payload: > > Files .js .jse .css .wsh .sct and .hta are not affected. > > Instead of .jpg and .jpeg, .zip and .rar files are destroyed > > Instead of .mp3 and .mp2, hidden copies of .asm and .pas > > files are made . > > > > > >VBS/Iloveyou.G > >-------------- > > > >A mail with virus contains: > > Subject: > > Mothers Day Order Confirmation > > Body: > > We have proceeded to charge your credit card for the amount > > of $326.92 for the mothers day diamond special. > > We have attached a detailed invoice to this email. > > Please print out the attachment and keep it in a safe place. > > Thanks Again and Have a Happy Mothers Day! > > [EMAIL PROTECTED] > > Attached file: > > mothersday.vbs > > > >A file sent via mIRC is: > > mothersday.HTM > > > >Comment lines at the beginning of the virus are replaced with: > > rem hackers.com > > rem by: hackers.com > > > >Start page in Explorer is randomly set to one of this values: > > http://www.hackers.com > > http://www.l0pht.com > > http://www.2600.com > > http://www.hackers.com > > > >Changes in payload: > > Instead of .jpg and .jpeg, .bat and .ini files are destroyed . > > > > > >VBS/Iloveyou.H > >-------------- > > > >A mail with virus contains: > > Subject: > > Dangerous Virus Warning > > Body: > > There is a dangerous virus circulating. > > Please click attached picture to view it and learn to avoid it. > > Attached file: > > virus_warning.jpg.vbs > > > >Sending the virus via IRC will not work because virus > >creates file: > > Urgent_virus_warning.htm > >But tries to send file: > > _virus_warning.htm > > > >Comment lines at the beginning of the virus are removed. > > > >Start page in Explorer is randomly set to: > > http://skycable.tucows.com/files2/setup24.exe > > > >Changes in payload: > >Files with .wav .txt .gif .doc .htm .html and .xls extension > >are also destroyed. > > > > > >VBS/Iloveyou.I > >-------------- > > > >A mail with high priority setting, the sender is set to > >[EMAIL PROTECTED] It contains > > > > Subject: > > Virus ALERT!!! > > Body: > > Dear Symantec customer, > > Symantec's AntiVirus Research Center began receiving reports > > regarding VBS.LoveLetter.A virus early morning on May 4, 2000 GMT. > > This worm appears to originate from the Asia Pacific region. > > Distribution of the virus is widespread and hundreds of thousands > > of machines are reported infected. > > The VBS.LoveLetter.A is an Internet worm that uses Microsoft > > Outlook to e-mail itself as an attachment. > > The subject line of the e-mail reads ILOVEYOU, with the attachment > > titled LOVE-LETTER-FOR-YOU.TXT.VBS. > > Once the attachment is opened, the virus replicates and sends > > an e-mail to all e-mail addresses listed in the address book. > > The virus also spreads itself via Internet relay chat and infects > > files on local and remote drives including files with extensions > > vbs, vbe, js, sje, css, wsh, sct, hta, jpg, jpeg, mp3, mp2. > > Users should exercise caution when opening e-mails with this > > subject line, even if the e-mail is from someone they know, > > as that is how the virus is spread. > > Symantec Corp. today announced availability of the virus definition > > to detect, repair and protect users against the VBS.LoveLetter.A virus. > > This definition is available now via Symantec's LiveUpdate and can > > also be downloaded from the following web sites: > > http://www.symantecstore.com/AF74211/promo/loveletter > > http://www.digitalriver.com/symantec > > Also as a quick solution Symantec Corp. offers Visual Basic Script > > to protect your PC against this worm. (See attached.) > > Note! When executed, this script will protect Your PC from being > > INFECTED by VBS.LoveLetter.A virus. > > To cure already infected PC's download Norton Antivirus Updates > > mentioned above. > > Symantec Corporation - > > a world leader in internet security technology. > > Attached file: > > protect.vbs > > > >File sent via mIRC is: > > protect.htm > > > >Comment lines at the beginning of the virus are replaced with: > > rem rewritten by Ommenc / directly from HELL!!! / > > <Fuck teachers, burn schools > > > >Start page in Explorer is set to: > > http://3doc.dailypussy.com/gallery/bunny.html > > > >Other Explorer related changes in registry are: > > Local Page: is set to copy of virus > > Search page: http://astalavista.box.sk > > Default_Page_URL: http://www.persiankitty.com > > Default_Search_URL: http://www.thecrack.net > > > >Window Title is set to: > > Mocro$oft Internet Exploder by Ommenc > > > >Changes in payload: > > Files .bat and .com are also destroyed. > > > >VBS/Iloveyou.J > >-------------- > > > >Thoroughly commented variant of the original VBS/Iloveyou.A. > >The difference is only in more synoptical source code and > >comments explaining working of particular virus parts. > > > >Comment lines at the beginning of the virus are added with: > > > > Comments beginning with ' added by The Hidden May 4 2000 > > > > > >Detection and removal > >===================== > > > >AVG is with last update released on May 4th (145) > >able to detect all known variants: > > > >ILOVEY_A.VBS Virus identified VBS/Iloveyou > >ILOVEY_B.VBS Virus found VBS/Iloveyou > >ILOVEY_C.VBS Virus found VBS/Iloveyou > >ILOVEY_D.VBS Virus found VBS/Iloveyou > >ILOVEY_E.VBS Virus found VBS/Iloveyou > >ILOVEY_F.VBS Virus found VBS/Iloveyou > >ILOVEY_G.VBS Could be infected VBS/Iloveyou > >ILOVEY_H.VBS Could be infected VBS/Iloveyou > >ILOVEY_I.VBS Virus found VBS/Iloveyou > >ILOVEY_J.VBS Virus found VBS/Iloveyou > > > >-- > >GRISOFT(c) SOFTWARE > >Virus Alert List > > > > > > > >================================================================== > >= If you want to unsubscribe this free announcement service, please > >= visit our web pages at http://www.grisoft.com/html/us_alert.cfm > >= and cancel your subscription. You can send email to > >= [EMAIL PROTECTED] with UNSUBSCRIBE avgviralert <your_email> > >= command in the message body, too. > > > -- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] Archive: http://www.mail-archive.com/[email protected]/
