Vulnerability Development mailing list archives

Re: New worm?


From: RichC () LOEHMANNS COM (Rich Corbett)
Date: Thu, 4 May 2000 10:29:30 -0400


I have received this in my company as well.  We have sent out a virus alert
to all users.  This does appear to be a new worm.  Please note the the
subject of the message is "ILOVEYOU".  Tell all of your users to simply
delete the message and not to try to view the attachment.

G'Luck

Richard Corbett
MIS Director
Loehmann's Inc.

-----Original Message-----
From: Blue Boar [mailto:BlueBoar () THIEVCO COM]
Sent: Thursday, May 04, 2000 10:07 AM
To: VULN-DEV () SECURITYFOCUS COM
Subject: New worm?

I received two copies of this worm-looking thing this morning.  I don't
have time to look myself before I head out, but I thought the list
might be interested.  The second copy looks like someone who got it
themselves and wants to know what it is.

Attached is a zip, and inside it is another zip of the two files
wrapped in their original mail headers.. so it should be pretty
safe unless you go out of your way to run them.  In which case,
caveat subscriber.

It looks like VBScript, and has a .vbs extension, and diddles
with reg keys, so I assume it's after windows boxen with WSH
installed.

                                BB


Current thread: