virus alert NO HOAX
A new virus named vbs_loveletter was discovered 2000/05/04 at
11h00.Currently Pattern 693 detects the the virus but is not able to
remove the virus. All mail systems is protected against the virus
but message with subject line I love you might still be spreading
although they are not harmful.
Do not open email messages with I LOVE YOU in the subject.
If you receive such mail delete it.
More information
Note: This virus is currently in the wild and is spreading rapidly
This VBScript is an auto-spamming worm which spreads by
sending an email message with the attached file “LOVE-LETTER-
FOR-YOU.TXT.vbs” to all addresses listed in a user’s Outlook
address list
Once executed this computer worm modifies registry and drops
files for it to spread. It replicates via Microsoft Outlook by sending
an email with an attachment file LOVE-LETTER-FOR-
YOU.TXT.vbs to all email addresses listed in the address list. It
also propagates using mIRC by modifying the script.ini. After
connecting to a chat server using mIRC, the virus initiates a DCC
send to all the users in the current channel and sends a copy of
itself. It is also capable of infecting files with specific extensions
Solution
Trend customers
Keep your pattern file and scan engine updated. Trend Micro
antivirus software can clean or remove most types of viruses.
Certain viruses, such as Trojans, scripts, overwriting viruses and
joke programs which are identified as “uncleanable”, should simply
be deleted.
Cleaning the virus
Delete all vbs extension files with size of 11k.
Remove the following from the registry.
HKLM\Software\Microsoft\Windows\Currentversion\run Deletekey
Mskernel32.Vbs
HKLM\Software\Microsoft\Windows\Currentversion\runservices
Deletekey Win32dll.vbs
=================================
From our DATA center.
Marius