General discussion

Locked

lovebug virus

By Seadogs ·
Does anyone know where you can get a fix for the lovebug virus? It looks like it just came up today, works very similar to the Melissa virus, but really fast. Thanks,

This conversation is currently closed to new comments.

19 total posts (Page 2 of 2)   Prev   01 | 02
| Thread display: Collapse - | Expand +

All Comments

Collapse -

lovebug virus

by Joesyl In reply to lovebug virus

It will be hard for you to get on the virus vendor (Mcafee, NAI, Symantec, ..) website since they are heavily bombarded now. Try www.cnet.com. I got updated DAT file yesterday afternoon from there. Good luck!

Collapse -

lovebug virus

by Seadogs In reply to lovebug virus

Poster rated this answer

Collapse -

lovebug virus

by Its a secret In reply to lovebug virus

VBS_LOVELETTER
Risk rating:

Destructive: Y

Aliases:
LOVELETTER, Love Bug, Very Funny

Description:
Note: This virus is currently in the wild and is spreading rapidly. As of now there are five variants for this virus. Read more about them.

This VBScript virus like Melissa uses Microsoft Outlook to send email with an attachment file “LOVE-LETTER-FOR-YOU.TXT.vbs” to all email addresses listed in the address list. This email will have the subject: “ILOVEYOU”, body: “kindly check the attached LOVELETTER coming from me.” And a file attachment with the virus. LOVELETTER also propagates using mIRC. After connecting to a chat server using mIRC, the virus sends a copy of itself “LOVE-LETTER-FOR-YOU.HTM” to all users in the same channel as the infected user.

This virus has a destructive payload, it overwrites files with specific extensions with its virus codes. This action eliminates the host file and what remains is the file containin

Collapse -

lovebug virus

by Seadogs In reply to lovebug virus

Poster rated this answer

Collapse -

lovebug virus

by Its a secret In reply to lovebug virus

Solution:


Click START|RUN
Type REGEDIT and hit ENTER key

In the left panel, click the "+" to the left of the following:
HKEY_LOCAL_MACHINE, Software, Microsoft, Windows, CurrentVersion, Run
In the right panel, search for the registry key that contains the data value of “Windows\System\ MSKernel32.vbs" and “\WIN-BUGSFIX.exe”. These are the registry keys that grant the capability to load the worm whenever Windows starts up.
In the right window, highlight the registry key that loads the file and press the DELETE key.
Search for the registry key that contains the data value of “Windows\System\ Win32DLL.vbs". In the right window, highlight the registry key that loads the file and press the DELETE key.
Exit the registry.
Click START|SHUTDOWN. Choose "Restart in MS-DOS mode" and click OK.
After the computer has restarted, the default directory should C.
Subsequently, type “DEL WIN-BUGSFIX.exe”.
Press CTRL+ALT+DEL and allow Windows to restart.

Collapse -

lovebug virus

by Seadogs In reply to lovebug virus

Poster rated this answer

Collapse -

lovebug virus

by sframes In reply to lovebug virus

probably to late but McAfee and Norton and also Mijenix all have a fix for it. If life isn't tough enough, it's been cloned and now goes out as "Virus Update." If you do get it, there are some pretty easy steps you can take to eliminate it by editing it out using regedit. Be warned the virus will erase all your .extensions in less than 2 minutes and replace them with it's own. If that happens, it easier to reforamt the drives and start from ground zero. Some fo the virus labs have an advance warning system that you can sign up for. Short term and long term this is a good way to stay aware.

Collapse -

lovebug virus

by Seadogs In reply to lovebug virus

Poster rated this answer

Collapse -

lovebug virus

by Seadogs In reply to lovebug virus

This question was closed by the author

Back to Desktop Forum
19 total posts (Page 2 of 2)   Prev   01 | 02

Related Discussions

Related Forums