Arrow-right Camera
The Spokesman-Review Newspaper
Spokane, Washington  Est. May 19, 1883

Malicious Love Bug Mutation New E-Mail Virus Changes Its Shape To Avoid Detection

Add Spokesman-Review on Google
Jason Z. Cohen Los Angeles Daily News

A new and more powerful variant of the Love Bug virus is worming its way through the Internet, changing its name with every computer it infects.

The new virus works similarly to the love bug that infected computers worldwide recently, but its spread has been kept in check by security precautions.

The new program, which researchers have named VBS/NewLove.A Worm, exploits the Microsoft Outlook e-mail program to send itself to each person in the program’s address book.

The program constantly changes its length by altering the number of lines of code it is made up of, an effort to escape discovery by antivirus software that uses file size as a detection signature. In all cases, the program, written in the Visual Basic language, appends the extension .vbs to each document name.

Internet security service provider ICSA.net estimated the virus has affected hundreds of North American organizations, well short of the tens of thousands of organizations impacted by the earlier virus.

The number may get as high as a thousand organizations, said Peter Tippett, chief scientist at ICSA.net.

Experts said the outbreak was limited by awareness and preparedness developed by computer users as a result of the previous virus.

In Washington, Attorney General Janet Reno launched an FBI investigation into the new virus. Once it has been activated, the virus systematically deletes inactive files stored on the computer’s hard drive.

“The big thing that is different about this one is the level of destruction,” said Kevin Haley, group product manager for Symantec, maker of Norton Antivirus. “It will completely delete all of the files on a user’s system.”

Additionally, the virus is polymorphic, meaning it changes its look every time it is passed along, Haley said.

“It looks different for users, and it looks different for antivirus software,” he said.

Chuck Jackson, a computer consultant who repairs computers and networks for Encino, Calif.-based Fulton-Meyer Information Technology, said people need to be prepared.

“A lot of times, they’ll load an antivirus program on their computer, and they’ll think they’re safe,” he said. “In a time like this it should be updated almost daily.”

The virus takes advantage of a loophole in Microsoft’s Outlook e-mail program that was designed to allow users of hand-held devices to add e-mail addresses to the address books on their desktop computers.

On its Internet site, Microsoft has security patches available for Outlook 97, Outlook 98 and Outlook 2000. The patches contain various security enhancements.

Once it has established itself, the virus looks in the folder in which recently used documents are stored. Then, it picks the name of the most recently opened document and renames itself using that designation.

Both Haley and Jackson said users should look out for e-mail attachments that end in .vbs and delete them without opening them, even if they come from someone they know.

Haley said Symantec, like other antivirus software makers, had an update available early Friday.

“We posted it on our Web site and made it available to all of our users,” he said.

The newest virus has proved difficult to prepare for, he said. Rather than simply changing the virus profile that users routinely download, Haley said Symantec was forced to change the program software itself.

The upgrade takes 125 kilobytes of disk space and takes no more than a minute or two to download via a 56 Kb modem, he said.

Another potential effect of the virus is a slowing of traffic on the Internet, Jackson said.

“With all of those e-mails going out, it really affects the performance of the Net,” he said.

Earthlink Networks users were not affected on the system level by an increase in the amount of e-mail traveling the Internet, said spokesman Kurt Rahn.

The nation’s second-largest Internet service provider maintains a buffer in its service capacity so additional traffic does not significantly slow the system, he said.

“We haven’t really seen much more than a blip,” Rahn said.