Summary

Summary
Action
More Information
| Included in our products from | June 2000 (3.34) |
|---|---|
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Please read the instructions for removing Trojans.
More Information
The VBS/LoveLet-A worm attempts to download this trojan from a website and modifies the registry so that the file is run when the system boots.
When the trojan itself is run on the next reboot it also copies itself to C:\WINDOWS\SYSTEM\WINFAT32.EXE and changes the registry so that this new file is started on every Windows boot.
The trojan attempts to send a message to an email address in the Philippines with the subject "Barok... email.passwords.sender.trojan". The message contains information on the user's hostname, username, host IP address, remote access passwords and cache passwords.
