VBS/Newlove.a is a VB Script worm with virus qualities.

McAfee AVERT has assessed it as a HIGH-risk threat. This

worm searches all drives connected to the host system and

replaces all files  with copies of itself and it adds the

extension .VBS to the original filename. The original file

is then deleted. The worm uses Microsoft Outlook to send

copies of itself to all entries in the address book.

When this worm is first run, it places a copy of itself in

the Windows folder and gives itself a name from either the

Recent Documents folder, or uses a random name with a

random extension.

This worm will arrive in an email message with this format:

Subject: Starts with "FW: " and is either a name from the

Recent Documents folder or a random name

Message: Empty

Attachment: Is the randomly-selected VBS filename from the

Windows folder

This virus will run if Windows Scripting Host is installed.

Running the email attachment received either accidentally or

intentionally will install to the local system.

Reply via email to