|
||||||||||||||||||
![]() ![]() ![]() |
VBS/Loveletter.as
Aliases
VBS/Plan, VBS_Colombia
|
This is a variant of the VBS/Loveletter family. It contains similar routines as other variants and includes a date activated payload which attempts to disconnect all mapped drives from the local host on the network. One AntiVirus firm announced this as VBS/Plan in a press release. This worm contains this string which is not displayed: rem "Plan Colombia" virus
v1.0
If this Internet worm is run either intentionally or accidentally, it will install to the local system and also perform actions against files. This worm will copy itself
ot the local system in the following locations:
In the above, the random
name could have the following possible file extensions:
The filename itself is generated
using a random pick alternating between any letter in the alphabet, and
the vowel character set A, E, I, O, U. For instance, a possible filename
could be "bAlIr.BMP.vbs" Next, this worm will modify the registry to load
itself via the registry at Windows startup from these locations:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ reload = WINDOWS\reload.vbs After modifying the registry, it checks for the existence of the file "WINFAT32.EXE". If this file is found, it modifies settings for Internet Explorer to download three files from a web page. The three files are two .BMP files and one .TXT however the names of the files suggest being of .ZIP format - they are not. The three files copied to
the local system are:
These are then copied from
the Temporary Internet Files folder to the WINDOWS folder as:
The logo files are bitmap replacements for Windows startup and shutdown screens. The .txt is displayed at Windows startup due to a registry modification made by this worm: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\plan colombia = WINDOWS\important_note.txt After this, the worm writes
a file as:
Next, the worm will run an email routine to distribute itself via MAPI email. The email is variable and could have either of four possible formats. The Subject line with either be static (below) or a random 6 letters, and the body will either be static (below) or a random 10 letters: Subject =
The random name is predetermined in an earlier process mentioned above. After the email routine, this worm performs another action against the system and mapped drives. If this worm find files of type ".VBS" or ".VBE", it will overwrite and replace them with its own code. If this worm finds files of type ".js", ".jse", ".css", "wsh", "sct", "hta", ".jpg" or ".jpeg", it will first copy itself as that filename and add extension .VBS and delete the original file. If this worm finds files of type ".MP2" or ".MP3", it will set their attributes to hidden. Finally, if the current day
is September 7, this worm will display a message: "Dedicated to my best
brother=> Christiam Julian(C.J.G.S.)"
After this message is displayed and cleared, it will attempt to disconnect drives Z: through E: in reverse order. Removal Instructions Script,Batch,Macro and non
memory-resident:
Note1- Microsoft has released
an for Outlook as an email attachment security update. For a list of attachments
blocked and a general FAQ, visit this link.
Note2- It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled. PE,Trojan,Internet Worm and
memory resident:
|
||||||||
|
|
|||||||||
| [an error occurred while processing this directive] |
|
Howdy!!! Welcome to the McCann's PooR Farm I'm not with any school or schools, Just a disable grandpa with 17 grand kids, 1 Great grand Kid Sorry! about all of the adds, Our Cost just keeping going up. Please click on one of them and help us out. or Send $1.00 U.S. to: McCann's Poor Farm 20509 Lawrence 2207 Aurora, Mo. 65605-7275 Thank You, Junior McCann Webmaster and the GrandKids See what the experts have to say about the McCann's Poor Farm Web Page Legal Disclaimer - We Are in no way connected with any School and or Companies linked to this page. Links are provided as a courtesy only. |
Argentina, Australia, Austria, Belarus, Belgium, Bermuda, Brazil, Brunei Darussalam, Bulgaria, Canada, Chile, Columbia, Costa Rica, Croatia, Croatia/Hrvatska, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Korea, Korea, Republic of, Latvia, Lebanon, Lithuania, Luxembourg, Macedonia, Malaysia, Mexico, Moldova, Netherlands, New Calendonia, New Zealand, Norway, Old style Arpanet, Papua New Guinea, Peru, Philippines, Poland, Portugal, Romania, Russian Federation, Saudi Arabia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Turkey, Uganda, Ukraine, United Arab Emirates, United Kingdom, United States, Uruguay, USA Government, USA Military, Viet Nam |
|
Tell A Friend about this Page |
Tell me when this page is updated |
|
|
Put a Link on your Web Page
- Legal Disclaimer - |