As a collection of my peers and betters, I would like to present the attached message for your review and comment. I am trying to explain the current outbreak of viruses to our customer base. We seem to be getting a lot of delayed hits, mostly it seems from folks with Email accounts with more than one ISP. Anyway the customer base goes from MCSE (+) to "Hey I just got me one of them computer things". Please help me fine tune this and feel free to copy any of it that may be of use to you.
How to beat the ILOVEYOU and other Visual Basic(VBS)/JScript viruses There are steps you can take to avoid getting it - and to get rid of it if you're already infected. Please read this entire document before attempting any changes to your system settings. NOTE: If you are unsure of how to do this or have any reservations about your ability to do this correctly, please contact your local computer professional. If you computer is under warranty contact the manufacturers support department and they will be glad to assist you: -*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*- On May 8, 2000 the ILOVEYOU worm (a.k.a.,VBS.LoveLetter.A) spread rapidly across the globe affecting users of Microsoft Windows running Microsoft Outlook/Outlook Express. And as it spread, a number of variants with slightly different presentation and payload joined the stampede. Now just 10 days later a new and different visual basic scripted (VBS) virus has been loosed. While not as quick spreading it is infinitely more serious. Where the ILOVEYOU virus and its imitators merely attacked certain types of files, this new virus attacks ever file it can access. The previous worms infect VBScripts, mIRC users and some files on your hard drive (namely .jpg and .mp3 files). Here are basic steps you can take to avoid infection, and what to do if you are already infected by the worm that gives love a bad name. What makes these viruses so dangerous is the easy to use yet powerful scripting language they are written in. The average, first year computer student learns the basics of the Visual Basic computer language. Microsoft created the Visual Basic programming language and all of their products are optimized to utilize it. One of the more powerful tools that supports it is the Windows Scripting Host (WSH) that is integrated in and installed with Microsoft's Windows 98/2000. It can also be installed on Windows 95/NT machines when Internet Explorer 5.0, OutLook 2000, and OutLook Express 5.0 are installed. WSH default mode on install is "ON" so it will automatically run programming written in Visual Basic (VBS) and JScript languages. Another Windows default setting that this series of virus's exploits is set in the Windows Explore (not to be confused with Internet Explorer). It hides the extensions of known file types. This allows the attached virus file named "Love-Letter-For-You.txt.vbs." to appear as "Love-Letter-For-You.txt.". Windows knows the ".Vbs" (also covers the .vbe, .js, .css, .sct extensions as well) file type and therefore hides the last part/extension of visual basic files. The computer user only sees what appears to be a harmless text file attached to the e-mail message in their inbox. The virus is unleashed when the unsuspecting user clicks on the extension to open and read the alleged text attachment. All of the worms make changes to the Windows registry and copies the Outlook address book. They all then e-mails themselves to all of your contacts. (Previously, viruses such as Melissa and its variants only chose the first 50 addresses.) This new worm has been overloading e-mail servers around the world. Luckily, users of Mac OS, Linux, and other OSes are not affected. However, anyone can pass it on by forwarding the infected e-mail. The original variant arrives as e-mail with the subject line "I Love You" and an attachment named "Love-Letter-For-You.txt.vbs." Opening the attachment infects your computer. The infection first scans your PC's memory for passwords, which are sent to a Web site in the Philippines that has since been shut down. The infection then replicates itself to everyone in your Outlook address book. Finally, the infection corrupts files ending with .vbs, .vbe, .js, .css, .wsh, .sct, .hta, .jpg, .jpeg, .mp2, .mp3 file extensions. The new virus while named NEWLOVE is not related to the previous ILOVE YOU virus. It has a new and deadlier payload as well as a polymorphic ability to change as it spreads. It also has an added ability to pick, at random a new name for it's self as it spreads. It randomly picks a filename from the user's list of recently opened documents. It then sends it's self out via Email to all of the addresses in the infected computers Outlook/Outlook Express address book. This name change makes it far tougher to screen/block. Previously there were a fixed number of ways to say ILOVEYOU: Love Bug Susitikim, Lithuania Very Funny Joke Mother's Day Virus Warning Virus Alert!!! Brainstorm Important Read Carefully!! Unnamed I Cant Believe This!!! Arab Air Variant Test Yeah, Yeah LOOK! Bewerbung There are some easy steps to prevent your computer from becoming infected. 1. Do not open e-mail with any of the above suspect subject lines no matter who sent it. This is the ILOVEYOU virus and is very destructive. If you receive the ILOVEYOU message, delete it from your system immediately. Do not be lax about other messages, just because they do not have one of the known subject lines listed above. There is the new NEWLOVE virus as well variants of ILOVEYOU. It is not alarmist to expect that there will also be variants of the NEWLOVE virus as well. 2. If you do receive e-mail with the worm, delete the message and contact the person you received the message from so he can eradicate the worm. A rule to live by is: Never open attachments included with e-mail unless it goes through an anti-virus tool scan first. Also, never open attachments from unknown addresses; these are often carriers of viruses and worms. 3. Download an anti-virus tool to screen and eradicate the virus. For ongoing protection, install an anti-virus program to prevent viruses from infecting your system. A good anti-virus program will scan all vulnerable parts of your system quietly in the background and detect, repair, and delete known viruses; it will even alert you to virus-like activity in case an unknown virus creeps on to your system. We recommend you use any of the leading anti-virus products currently available at your local computer store or online. In general, always have: A current anti-virus software on your system. Update it at least once a month, minimum, with the latest virus definitions (signatures), so that your anti-virus program can detect the newest viruses. (new anti-virus definitions are published weekly) 4. We strongly recommended that if you do not use Visual Basic scripting or JScript in the course of your average day, you should disable/turn off the WSH. To disable/turn off the WSH do the following: Click on your "Start" button Click on "Settings" Click on "Control Panel" Click on "Add/Remove Programs" Click on the "Windows Setup" tab Click on "Accessories" to highlight it Click on the "Details" button Uncheck "Windows Scripting Host" if it is checked Click "Apply" to save any changes Click "OK" to close the "Add/Remove Program Properties" menu Close "Control Panel" 5. We also recommend that you disable/turn off the "Hide file extensions for known file types" option in Windows Explore. To disable/turn off the "Hide file extensions for known file types" do the following: Double click on the "My Computer" icon Click on "View" Click on "Folder Options" Click on the "View" tab Uncheck "Hide file extensions for known file types" if it is checked Click "Apply" to save any changes Click "OK" to close the "Folder Options" menu Close the "My Computer" window IF YOU ARE INFECTED ... All major anti-virus software companies have released updates allowing their software to detect and defend against the all of the current variations of the ILOVEYOU virus and also have special updates to deal with the NEWLOVE virus as well.. The latest virus definitions are available for: Norton AntiVirus 4.0, 5.0 and 2000 Norton AntiVirus 2.0 through 4.0 (DOS, Win3.x) Norton AntiVirus for NetWare McAfee VirusScan/Dr. Solomon Also available: LoveScan, to detect and eliminate the worm from Microsoft Exchange servers. Additionally, if your PC is infected, delete the following files from your infected system: MSKernel32.vbs in the Windows System directory Win32DLL.vbs in the Windows directory LOVE-LETTER-FOR-YOU. TXT.vbs in the Windows System WinFAT32.EXE in the Internet download directory script.ini in the mIRC directory
