Russell Kent wrote:
A little knowledge is a dangerous thing. *sigh*
I've opened the "Love bug" virus inside a deconstruction tool. It is a Visual
Basic Script (which is what the .vbs extension denotes). It is a nasty piece of
work. What follows is a list of the things it *attempts* to do. It's a
poorly-written program (as most viruses are, thankfully) so I cannot guarantee
that it actually succeeds at any of them:
1. Turn off the windows scripting timeout
Presumably this is so that if it (the virus) takes a long time, it won't be
thwarted by the system.
2. Reads a copy of itself into memory
3. Writes that copy into "MSKernel.vbs" (system dir), "Win32DLL.vbs" (Windows
dir), and "LOVE-LETTER-FOR-YOU.TXT.vbs" (system dir)
4. Creates some registry keys that cause the files "MSKernel3.vbs" and
"Win32DLL.vbs" to be run at system startup. The careful reader will notice
that these files have Visual Basic Script extensions. See previous step.
5. Pseudo-randomly sets the Internet Explorer's start page to one of:
http://www.skyinet.net/~young1s
http://www.skyinet.net/~angelcat/
http://www.skyinet.net/~koichi/
http://www.skyinet.net/~chu/
Note that the above are not the complete web addresses; there is somw
random-looking garbarge, ending with "/WIN-BUGSFIX.exe" I think the virus
author is trying to cause IE to download another payload the next time IE is
started. See the next item.
6. If the file WIN-BUGSFIX.exe exists in the IE downloaded files directory, then
set the system to run this file the next time the user start windows, and set
the IE start page to nothing (really "about:blank").
7. Creates a variant of itself as a web page (LOVE-LETTER-FOR-YOU.HTM) in the
system directory. This web-page variant has an embedded JavaScript that
creates the Trojan MSKernel32.vbs, and the JavaScript makes registry entries
that cause the MSKernel32.vbs to be run the next time Windows is started.
8. Opens the Outlook address book. This is where Netscape email users (like me)
get to gloat. :-)
9. For every entry in the Outlook address book, if there doesn't exist an
"already sent" registry flag (that the virus creates later), then send a copy
of the virus to that user, and create the "already sent" registry entry.
Now we begin the *destructive* part of the payload.
1. For every drive on the system, do a recursive search for files:
1. of the form: *.vbs, *.vbe
(Over-write with the virus script)
2. of the form: *.js, *.jse, *.css, *.wsh, *.sct, *.hta, *.jpg, *.jpeg,
*.mp3, *.mp2
(Replace with the virus script and rename to *.vbs)
3. of the form: "mirc32.exe", "mlink32.exe", "mirc.ini", "script.ini",
"mirc.hlp"
(Create/replace script.ini file with an IRC initialization script that
sends the virus in HTML form to whomever you chat with.
All-in-all, a real piece of nasty crap, but not subtle or terribly clever.
If any of the list members got clobbered with this and haven't got help already,
I'm available for consultation. I can provide exact registry entries to those who
are trying to put the pieces back together, but the overwritten files will need to
be restored from backups.
Russell Kent
Paul wrote:
"Sneed, Glen" wrote:
This virus has got our mail servers crawling. I though you
may want to let our News Group know so none of us who use MS mail pass it
along. I does affect the MS Windows/NT registry.
VIRUS SUMMARY: ILOVEYOU (in the subject box)
The email has the subject of "ILOVEYOU" with
the email body as "kindly check the attached LOVELETTER coming from me"
followed by an attachment called LOVE-LETTER-FOR-YOU.TXT.VBS. It is a
potentially lethal virus that affects Windows registry settings and may
delete files from your hard drive. It is transmitted by opening the
attachment similar to melissa.
PREVENTION:
Do not open messages that contain the above content.
Glenn Sneed
The Aircraft Rotary Engine Newsletter. Powered by Linux.
http://home.earthlink.net/~rotaryeng/ http://www.linux.org