Another solution for removal and also information about i wub u trojans 4 other 
variants:



F-Secure Anti-Virus detetects LoveLetter worm with the latest updates. 

The manual removing of LoveLetter worm could be done by deleting the following files 
from the infected machine: 

-all .VBS files from all the drives and from all sub directories;
-the file LOVE-LETTER-FOR-YOU.HTM from Windows System directory
-WIN-BUGSFIX.EXE and WINFAT32.EXE from Internet explorer
download directory.

VARIANT: LoveLetter.B
This variant uses another message subject when spreads: 
Subject:    Susitikim shi vakara kavos puodukui...
Body:       kindly check the attached LOVELETTER coming from me.
Attachment: LOVE-LETTER-FOR-YOU.TXT.vbs

LoveLetter.B contains the following comments in its code: 
Modified Lameris Tamoshius / Lithuania (Tovi systems)

VARIANT: LoveLetter.C

This variant propagates in a message with 

Subject:    fwd: Joke
Attachment: Very Funny.vbs

VARIANT: LoveLetter.D

This variant is a slightly modified variant from VBS/LoveLetter.A. 

VARIANT: LoveLetter.E

VBS/LoveLetter.E spreads itself in a message that is as follows: 
Subject:    Mothers Day Order Confirmation
Body:       We have proceeded to charge your credit card for the
amount of $326.92 for the mothers day diamond special.
We have attached a detailed invoice to this email.
Please print out the attachment and keep it in a safe
place.Thanks Again and Have a Happy Mothers Day!
[EMAIL PROTECTED]
Attachment: mothersday.vbs

Additionally, this variant deletes all files with the extension ".ini" and ".bat" 
instead of ".jpg" and ".jpeg". 

This variant does not attempt to download the "WIN-BUGSFIX.exe" from the Internet, 
however it modifieds the Internet Explorer start page. 


---------- Original Message ----------------------------------
From: Len Conrad <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date: Thu, 04 May 2000 19:32:48 +0200

>I picked this up on another list, if it works, sure beats re-installing Win:
>
>=============================
>Just delete the following things to get rid of the Viri:
>
>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BUG
>SFIX
>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKerne
>l32 und
>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
>\Win32DLL
>
>also for a WIN-BUGSFIX.EXE File on your Harddisk and delete it.
>
>The Infected Email Recieptens are lstet here in the Registry (So you can
>warn them):
>
>HKEY_CURRENT_USER\Software\Microsoft\WAB\
>=====================
>
>Please visit http://www.ipswitch.com/support/mailing-lists.html 
>to be removed from this list.
>

--
--------------------------------------------------------------
- Walter Saarimaa
- PC-Support Engineer
- Finnish Game and Fisheries Research Institute
-[Begin Signature]-----------------------------------------
Tech Support Golden Rule
Anyone who asks a question is a moron.
The people who don't ask questions are morons too.

--
Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to