Another solution for removal and also information about i wub u trojans 4 other variants: F-Secure Anti-Virus detetects LoveLetter worm with the latest updates. The manual removing of LoveLetter worm could be done by deleting the following files from the infected machine: -all .VBS files from all the drives and from all sub directories; -the file LOVE-LETTER-FOR-YOU.HTM from Windows System directory -WIN-BUGSFIX.EXE and WINFAT32.EXE from Internet explorer download directory. VARIANT: LoveLetter.B This variant uses another message subject when spreads: Subject: Susitikim shi vakara kavos puodukui... Body: kindly check the attached LOVELETTER coming from me. Attachment: LOVE-LETTER-FOR-YOU.TXT.vbs LoveLetter.B contains the following comments in its code: Modified Lameris Tamoshius / Lithuania (Tovi systems) VARIANT: LoveLetter.C This variant propagates in a message with Subject: fwd: Joke Attachment: Very Funny.vbs VARIANT: LoveLetter.D This variant is a slightly modified variant from VBS/LoveLetter.A. VARIANT: LoveLetter.E VBS/LoveLetter.E spreads itself in a message that is as follows: Subject: Mothers Day Order Confirmation Body: We have proceeded to charge your credit card for the amount of $326.92 for the mothers day diamond special. We have attached a detailed invoice to this email. Please print out the attachment and keep it in a safe place.Thanks Again and Have a Happy Mothers Day! [EMAIL PROTECTED] Attachment: mothersday.vbs Additionally, this variant deletes all files with the extension ".ini" and ".bat" instead of ".jpg" and ".jpeg". This variant does not attempt to download the "WIN-BUGSFIX.exe" from the Internet, however it modifieds the Internet Explorer start page. ---------- Original Message ---------------------------------- From: Len Conrad <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Thu, 04 May 2000 19:32:48 +0200 >I picked this up on another list, if it works, sure beats re-installing Win: > >============================= >Just delete the following things to get rid of the Viri: > >HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BUG >SFIX >HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKerne >l32 und >HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices >\Win32DLL > >also for a WIN-BUGSFIX.EXE File on your Harddisk and delete it. > >The Infected Email Recieptens are lstet here in the Registry (So you can >warn them): > >HKEY_CURRENT_USER\Software\Microsoft\WAB\ >===================== > >Please visit http://www.ipswitch.com/support/mailing-lists.html >to be removed from this list. > -- -------------------------------------------------------------- - Walter Saarimaa - PC-Support Engineer - Finnish Game and Fisheries Research Institute -[Begin Signature]----------------------------------------- Tech Support Golden Rule Anyone who asks a question is a moron. The people who don't ask questions are morons too. -- Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list.
