Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:
Type:Worm 
Size:12.607 Bytes 
Origin: 
Date:08-18-2000 
Damage:Sent by email. 
VDF Version:6.20.00.00 
Danger:Low 
Distribution:Medium 

DistributionVBS.LoveLetter spreads over Windows email program, using all Outlook saved addresses. It only affects email systems with active contents.

Technical DetailsThe virus makes a registry entry for skipping this step at further calls:
HKEY_CURRENT_USER\Software\ACH0""=1
Then, the virus checks for the following key:
HKEY_CURRENT_USER\Software\UBS\UBSPIN\Options\Datapath
If the key is found, the virus tries to download a program, if not yet available, from one of the three FTP servers 165.121.181.24/hcheck.exe; alw.nih.gov/incoming/hcheck.exe; archive.egr.msu.edu/incoming/hcheck.exe and runs it. This file, a password stealer program, is no longer available on the servers. Then it sends the selected file, included in the above registry entry, to the following email addresses: ct102356@excite.com; acch01@netscape.net; deroha@mailcity.com. It also saves a copy of the file in CP_21863.NLS file in Windows system directory.
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .