corsasport.co.uk
 

Corsa Sport » Message Board » General Chat » pc help » Post Reply

Post Reply
Who Can Post? All users can post new topics and all users can reply.
Icon:
Formatting Mode:
Normal
Advanced
Help

Insert Bold text Insert Italicized text Insert Underlined text Insert Centered text Insert a Hyperlink Insert Email Hyperlink Insert an Image Insert Code Formatted text Insert Quoted text
Message:
HTML is Off
Smilies are On
BB Code is On
[img] Code is On
Post Options: Disable smileys?
Turn BBCode off?
Receive email notification of new replies?

Macca_G

posted on 18th Feb 05 at 15:35

It tells you what it is and how to get rid of it..


Dan

posted on 18th Feb 05 at 15:34

???


Macca_G

posted on 18th Feb 05 at 15:32

Read the bottom bit :thumbs:


Macca_G

posted on 18th Feb 05 at 15:31

VBS.LoveLetter.CA spreads using Microsoft Outlook. It attempts to email itself to all contacts that have not yet been targeted by the worm. The payload of this worm overwrites files of certain extensions with its own code.

NOTE: Virus definitions prior to March 2, 2001 detected this as VBS.LoveLetter.Variant.

The subject is one of the following:

MERRY X-MAS FROM MICROSOFT. =PLEASE VISIT => (http://WWW.MICROSOFT.COM)<=
[String of 6 random characters]
[No Subject]

The body of the email is one of the following:
STAR F**KERS INC. EVEN TRENT KNOWS ITS TRUE
[String of 10 random characters]
[No Body Text]


Also Known As: VBS.LoveLetter.Variant, I-Worm.Loveletter, VBS/LoveLetter@MM

Type: Worm
Infection Length: 12,477 bytes



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP







Virus Definitions (Intelligent Updater) *
September 29, 2000


*
Intelligent Updater definitions are released daily, but require manual download and installation.
Click here to download manually.

**
LiveUpdate virus definitions are usually released every Wednesday.
Click here for instructions on using LiveUpdate.







Wild

Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy
Threat Metrics


Wild:
Low
Damage:
Medium
Distribution:
High



Damage

Payload Trigger: When VBS.LoveLetter.CA runs. If the date is December 25th, a special payload is triggered.
Payload:
Large scale e-mailing: All addresses are targeted once.
Modifies files: Overwrites files with certain extensions.
Degrades performance: On December 25th, all network drives are removed and a dialog box appears.
Distribution

Subject of email: MERRY X-MAS FROM MICROSOFT. =PLEASE VISIT => (http://WWW.MICROSOFT.COM)<=, [Random String of 10 Characters], or [No Subject]
Name of attachment: [Random String].VBS
Size of attachment: 12,477 Bytes
Target of infection: Files with the following extensions: .css, .hta, .jpeg, .jpg, .js, .jse, .mp2, .mp3, .sct, .vbe, .vbs and .wsh


When executed, VBS.LoveLetter.CA copies itself to \System\Linux32.vbs, Windows\Reload.vbs, and \System\[Random File Name].vbs.

The registry is modified so that when Microsoft Internet Explorer starts, it downloads three additional files. These files are then integrated into the system so that they start automatically.

After downloading the additional files it resets the Internet Explorer start page to a pornographic Web site.

VBS.LoveLetter.CA searches out specific files on all available drives, including mapped network volumes, and overwrites them with its own code. Files with the following extensions are targeted:

.css
.hta
.jpeg
.jpg
.js
.jse
.mp2
.mp3
.sct
.vbe
.vbs
.wsh

If the date is December 25, the following message appears:

EVEN TRENT KNOWS ITS TRUE=>STAR F**KERS INC.
Att. [random word] (REDRUM)


An attempt is then made to remove all network drives.





Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.


Delete all files detected as VBS.LoveLetter.CA.





Write-up by: Andre Post


:thumbs:


Ian

posted on 18th Feb 05 at 15:26

Sounds like a virus which was popular a few years ago. It deletes all images and video and replaces them with copies of itself.


Macca_G

posted on 18th Feb 05 at 15:24

Goto www.pandasoftware.com do the active scan - if its a virus this will sort it ;)

[Edited on 18-02-2005 by Macca_G]


LukeGSi

posted on 18th Feb 05 at 15:23

Stop downloading porn :P


Dan

posted on 18th Feb 05 at 13:03

i should be doing my conversion!!

but dad has a 30ft container in the air, held up by a few bits of wood and keeps looking 2 fall...im staying clear..

he is insane


willay

posted on 18th Feb 05 at 12:54

its friday, turn your pc off and go ruin your girlfriend.


willay has spoken. :thumbs:


Dan

posted on 18th Feb 05 at 12:53

what the hell is i?? what do i do?? donmt wanna fuck up pc


willay

posted on 18th Feb 05 at 12:51

you'd have the love letter virus then. :look:


Dan

posted on 18th Feb 05 at 12:51

wont let me...

virus checker just found summit called vbs.loveletter?


Macca_G

posted on 18th Feb 05 at 12:48

visual basic script..? probably just installed something that uses vbscipt as a default player for them... just chage them back..


Dan

posted on 18th Feb 05 at 12:42

why have all my jpegs and mpegs turned 2 vbscript?

is it a virus?