OK. Umiddelbart lyder det som en loveletter variant. Det er den mest udbredte VBScript-virus og et par af varianterne (f.eks. vbs_lovelettr.ba
http://www.antivirus.com/pc-cillin/vinfo/virusencyclo/default5.asp?VName=VBS_LOVELETTR.BA)
Det bedte bud er nok den. Her er hvad Trend Micro skriver om den:
Details:
Upon execution, this virus creates three copies of itself:
c:Windows\\System\\LINUX32.vbs
c:\\Windows\\reload.vbs
The third file has a random name and is dropped in the Windows directory. The file has one of the following extensions: GIF.vbs, .JPG.vbs, .BMP.vbs
The virus then creates the following registry keys:
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\
Run\\LINUX32 = \"LINUX32.vbs\"
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\
RunServices\\Reload = \"reload.vbs\"
HKCU\\Software\\Microsoft\\Internet Explorer\\
Download Directory = \"c:\\\"
Then the virus checks if the file c:\\Windows\\System\\WinFAT32.exe exists, and based on a random number, it downloads the following files:
http://members.fortunecity.com/plancolombia/macromedia32.zip
http://members.fortunecity.com/plancolombia/linux321.zip http://members.fortunecity.com/plancolombia/linux322.zip After downloading one the above mentioned zip files, the virus copies linux321.zip or linux322.zip as logos.sys and logow.sys to change the Windows startup and shutdown screens. The file macromedia32.zip is copied as \"Windows\\important_note.txt\" and is placed in the registry as:
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\
Run\\macromedia32 = \"important_note.txt\"
The virus then creates an HTM file, c:\\Windows\\System\\US-PRESIDENT-AND-FBI-SECRETS.HTM, which contains the VBScript virus in the <script> tag.
This VB Script virus is capable of sending itself via email as an attachment by using MS Outlook and its address book. The subject and body part of the email may change due to the random character generator of the virus.
The virus also searches for .VBS, .VBE, .JS, .JSE, .CSS, .WSH, .SCT, .HTA, .JPG, and .JPEG files and overwrites them with its code. It then changes the extension of the JPG and JPEG files to .VBS. Also, when the virus encounters .MP3 and .MP2 files, it hides them by setting their attributes to HIDDEN.
If the current system date is September 17, the virus displays a message box with the following text, and then removes all connected network drives from the infected system:
Dedicated to my best brother=>Christian Julian(C.J.G.S.)
Att. (M.H.M. TEAM)
Håber at dette hjælper!!