Threat Description

NewLove

Details

Category: Malware
Type: Worm
Platform: VBS
Aliases: NewLove, Herbie, Spammer

Summary


VBS/NewLove is a destructive and polymorpic VBScript worm similar to VBS/LoveLetter. Further information about VBS/LoveLetter is available at https://www.F-Secure.com/v-descs/love.shtml



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details



Variant:NewLove.A

VBS/NewLove.A uses Microsoft Outlook to spread in e-mail messages. The message that it sends looks like this:

  From:       name-of-the-infected-user     To:         random-name-from-address-book     Subject:    FW: (random_file_name.ext)     Body:     Attachment: (random_file_name.ext).vbs  

The worm replicates in an attachment with a random file name that has ".vbs" added to it. For example, "REPORT.DOC.vbs" or "Information on Jacks Birthday.txt.vbs". VBS/NewLove takes the random name from the recently opened files directory. If there is no files in that directory, it generates the name.

If the attachment is opened with the Notepad, the code of the worm can be seen:

Then the worm sends itself to each recipient in each Outlook address book - just like VBS/LoveLetter.

VBS/NewLove.A copies itself - with a random name - to the Windows System directory and to the Windows directory. It adds itself to the registry with a random key to the following registry hives:

		 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\  

Then the worm will go through all drives and subdirectories. For each file, the worm creates a new file using the same name with an additional extension ".vbs" and deletes the original file.

After this the machine can not boot any longer.

VBS/NewLove.A was reported to be somewhat in-the-wild on 19th of May, 2000. Detection of this worm was added to F-Secure Anti-Virus on 11:00 GMT 19th of May, 2000.





Technical Details:Katrin Tocheva and Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More