VBS/Newlove.a is a VB Script worm with virus qualities. McAfee AVERT has assessed it as a HIGH-risk threat. This worm searches all drives connected to the host system and replaces all files with copies of itself and it adds the extension .VBS to the original filename. The original file is then deleted. The worm uses Microsoft Outlook to send copies of itself to all entries in the address book. When this worm is first run, it places a copy of itself in the Windows folder and gives itself a name from either the Recent Documents folder, or uses a random name with a random extension. This worm will arrive in an email message with this format: Subject: Starts with "FW: " and is either a name from the Recent Documents folder or a random name Message: Empty Attachment: Is the randomly-selected VBS filename from the Windows folder This virus will run if Windows Scripting Host is installed. Running the email attachment received either accidentally or intentionally will install to the local system. |