As a collection of my peers and betters, I would like to present the
attached message for your review and comment.  I am trying to explain the
current outbreak of viruses to our customer base.  We seem to be getting a
lot of delayed hits, mostly it seems from folks with Email accounts with
more than one ISP.  Anyway the customer base goes from MCSE (+) to "Hey I
just got me one of them computer things".  Please help me fine tune this and
feel free to copy any of it that may be of use to you.
How to beat the ILOVEYOU and other Visual Basic(VBS)/JScript viruses

There are steps you can take to avoid getting it - and to get rid of it if you're 
already infected.  Please read this entire document before attempting any changes to 
your system settings. 

NOTE:  If you are unsure of how to do this or have any reservations about your ability 
to do this correctly, please contact your  local computer professional.  If you 
computer is under warranty contact the manufacturers support department and they will 
be glad to assist you:

-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-

On May 8, 2000 the ILOVEYOU worm  (a.k.a.,VBS.LoveLetter.A) spread rapidly across the 
globe affecting users of Microsoft Windows running Microsoft Outlook/Outlook Express. 
And as it spread, a number of variants with slightly different presentation and 
payload joined the stampede.  Now just 10 days later a new and different visual basic 
scripted (VBS) virus has been loosed.  While not as quick spreading it is infinitely 
more serious.  Where the ILOVEYOU virus and its imitators merely attacked certain 
types of files, this new virus attacks ever file it can access.  The previous worms 
infect VBScripts, mIRC users and some files on your hard drive (namely .jpg and .mp3 
files).  Here are basic steps you can take to avoid infection, and what to do if you 
are already infected by the worm that gives love a bad name.

What makes these viruses so dangerous is the easy to use yet powerful scripting 
language they are written in.  The average, first year computer student learns the 
basics of the Visual Basic computer language.  Microsoft created the Visual Basic 
programming language and all of their products are optimized to utilize it.  One of 
the more powerful tools that supports it is the Windows Scripting Host (WSH) that is 
integrated in and installed with Microsoft's Windows 98/2000.  It can also be 
installed on Windows 95/NT machines when Internet Explorer 5.0, OutLook 2000, and 
OutLook Express 5.0 are installed.  WSH default mode on install is "ON" so it will 
automatically run programming written in Visual Basic (VBS) and JScript languages.  
Another Windows default setting that this series of virus's exploits is set in the 
Windows Explore (not to be confused with Internet Explorer).  It hides the extensions 
of known file types.  This allows the attached virus file named 
"Love-Letter-For-You.txt.vbs." to appear as "Love-Letter-For-You.txt.".  Windows knows 
the ".Vbs" (also covers the .vbe, .js, .css, .sct extensions as well) file type and 
therefore hides the last part/extension of visual basic files.  The computer user only 
sees what appears to be a harmless text file attached to the e-mail message in their 
inbox.  The virus is unleashed when the unsuspecting user clicks on the extension to 
open and read the alleged text attachment.

All of the worms make changes to the Windows registry and copies the Outlook address 
book.  They all then e-mails themselves to all of your contacts.   (Previously, 
viruses such as Melissa and its variants only chose the first 50 addresses.) This new 
worm has been overloading e-mail servers around the world. Luckily, users of Mac OS, 
Linux, and other OSes are not affected.  However, anyone can pass it on by forwarding 
the infected e-mail.  The original variant arrives as e-mail with the subject line "I 
Love You" and an attachment named "Love-Letter-For-You.txt.vbs." Opening the 
attachment infects your computer. The infection first scans your PC's memory for 
passwords, which are sent to a Web site in the Philippines that has since been shut 
down. The infection then replicates itself to everyone in your Outlook address book. 
Finally, the infection corrupts files ending with .vbs, .vbe, .js, .css, .wsh, .sct, 
.hta, .jpg, .jpeg, .mp2, .mp3 file extensions. 

The new virus while named NEWLOVE is not related to the previous ILOVE YOU virus.  It 
has a new and deadlier payload as well as a polymorphic ability to change as it 
spreads.  It also has an added ability to pick, at random a new name for it's self as 
it spreads.  It randomly picks a filename from the user's list of recently opened 
documents.  It then sends it's self out via Email to all of the addresses in the 
infected computers Outlook/Outlook Express address book.  This name change makes it 
far tougher to screen/block.  Previously there were a fixed number of ways to say 
ILOVEYOU:

Love Bug
Susitikim, Lithuania
Very Funny Joke
Mother's Day
Virus Warning
Virus Alert!!!
Brainstorm
Important Read Carefully!!
Unnamed
I Cant Believe This!!!
Arab Air
Variant Test
Yeah, Yeah
LOOK!
Bewerbung

There are some easy steps to prevent your computer from becoming infected. 

1. Do not open e-mail with any of the above suspect subject lines no matter who sent 
it. This is the ILOVEYOU virus and is very destructive. If you receive the ILOVEYOU 
message, delete it from your system immediately. Do not be lax about other messages, 
just because they do not have one of the known subject lines listed above. There is 
the new NEWLOVE virus as well variants of ILOVEYOU.  It is not alarmist to expect that 
there will also be variants of the NEWLOVE virus as well.  

2. If you do receive e-mail with the worm, delete the message and contact the person 
you received the message from so he can eradicate the worm. A rule to live by is: 
Never open attachments included with e-mail unless it goes through an anti-virus tool 
scan first. Also, never open attachments from unknown addresses; these are often 
carriers of viruses and worms. 

3. Download an anti-virus tool to screen and eradicate the virus.  For ongoing 
protection, install an anti-virus program to prevent viruses from infecting your 
system. A good anti-virus program will scan all vulnerable parts of your system 
quietly in the background and detect, repair, and delete known viruses; it will even 
alert you to virus-like activity in case an unknown virus creeps on to your system.  
We recommend you use any of the leading anti-virus products currently available at 
your local computer store or online.

In general, always have:
A current anti-virus software on your system.  Update it at least once a month, 
minimum, with the latest virus definitions (signatures), so that your anti-virus 
program can detect the newest viruses. (new anti-virus definitions are published 
weekly)

4. We strongly recommended that if you do not use Visual Basic scripting or JScript in 
the course of your average day, you should disable/turn off the WSH.

To disable/turn off the WSH do the following:

Click on your "Start" button
Click on "Settings"
Click on "Control Panel"
Click on "Add/Remove Programs"
Click on the "Windows Setup" tab
Click on "Accessories" to highlight it
Click on the "Details" button
Uncheck "Windows Scripting Host" if it is checked
Click "Apply" to save any changes 
Click "OK" to close the "Add/Remove Program Properties" menu
Close "Control Panel"

5. We also recommend that you disable/turn off the "Hide file extensions for known 
file types" option in Windows Explore.

To disable/turn off the "Hide file extensions for known file types" do the following:

Double click on the "My Computer" icon
Click on "View"
Click on "Folder Options"
Click on the "View" tab
Uncheck "Hide file extensions for known file types" if it is checked
Click "Apply" to save any changes
Click "OK" to close the "Folder Options" menu
Close the "My Computer" window

IF YOU ARE INFECTED ... 

All major anti-virus software companies have released updates allowing their software 
to detect and defend against the all of the current variations of the ILOVEYOU virus 
and also have special updates to deal with the NEWLOVE virus as well.. The latest 
virus definitions are available for:

Norton AntiVirus 4.0, 5.0 and 2000
Norton AntiVirus 2.0 through 4.0 (DOS, Win3.x)
Norton AntiVirus for NetWare
McAfee VirusScan/Dr. Solomon
Also available: LoveScan, to detect and eliminate the worm from Microsoft Exchange 
servers.

Additionally, if your PC is infected, delete the following  files from your infected 
system:

MSKernel32.vbs in the Windows System directory
Win32DLL.vbs in the Windows directory
LOVE-LETTER-FOR-YOU. TXT.vbs in the Windows System
WinFAT32.EXE in the Internet download directory
script.ini in the mIRC directory

Reply via email to