TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
VBS_LOVELETTER
Overview

Malware type: VBScript

Aliases: IRC-Worm.VBS.Grammer (Kaspersky), VBS/LoveLetter.cy (McAfee), VBS.LoveLetter.Var (Symantec), VBS/Loveletter.B (Avira), VBS/LoveLet-G (Sophos),

In the wild: Yes

Destructive: Yes

Language: English

Platform: Windows 9x/NT

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 
VBS_LOVELETTER has several variants, which use different email subject, message body and attachments than the original virus. All variants are detected by Trend's latest pattern file.

This VBScript virus, like Melissa, uses Microsoft Outlook to send email with an attachment file "LOVE-LETTER-FOR-YOU.TXT.vbs" to all email addresses listed in the address list. This email has the subject: "ILOVEYOU", body: "kindly check the attached LOVELETTER coming from me." And a file attachment with the virus. LOVELETTER also propagates using mIRC. Using mIRC, the virus sends a copy of itself “;LOVE-LETTER-FOR-YOU.HTM”; to users in the same channel as the infected user.

This virus has a destructive payload, it overwrites files with specific extensions with its codes. This eliminates the host file and the file now contains the virus source code.

For additional information about this threat, see:
Solution
Technical Details

Description created: May. 18, 2000 5:12:26 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.