Sophos

Troj/LoveLet-A

Aliases
  • PWSteal.LoveLetter
Category
Type
What to do

Summary

 
Included in our products from June 2000 (3.34)
Detected by All Sophos products

Action

More Information

The VBS/LoveLet-A worm attempts to download this trojan from a website and modifies the registry so that the file is run when the system boots.

When the trojan itself is run on the next reboot it also copies itself to C:\WINDOWS\SYSTEM\WINFAT32.EXE and changes the registry so that this new file is started on every Windows boot.

The trojan attempts to send a message to an email address in the Philippines with the subject "Barok... email.passwords.sender.trojan". The message contains information on the user's hostname, username, host IP address, remote access passwords and cache passwords.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer