Sophos

VBS/VBSWG-D

Aliases
  • I-Worm.VBSWG2
  • VBS_VBSWG2.D
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 17 January 2005 09:45:09 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

Please follow the instructions for removing worms.

You will also need to edit the following registry entry, if it is present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
serves
C:\Windows\FirstLove.vbs

and delete it if it exists.

Close the registry editor.

More Information

VBS/VBSWG-D is Visual Basic script worm that spreads by email attachments.

When run the worm copies itself to C:\Windows\FirstLove.vbs.

VBS/VBSWG-D also attempts to create the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
serves
C:\Windows\FirstLove.vbs

HKCU\Software\
FirstLoveStory
1

The worm attempts to send emails to all email addresses registered in Outlook. The email sent by VBS/VBSWG-D has the following characteristics:

Subject line

First Love Story ...!!!

Message body

Hi,
Check the attachment

Attachment

C:\Windows\FirstLove.VBS

On February 14, the worm displays a message box with the message

"!@#5!@#p!@#1!@#d!@#3!@#y!@#### Happy Fucking Valentine ...!!! ###
!@#5!@#p!@#1!@#d!@#3!@#y!@#" and a title header "ValentineDay"

and then proceeds to shutdown the computer.

The message displayed by the VBS/VBSWG-D worm
The message displayed by the VBS/VBSWG-D worm.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer