Inside the 'ILOVEYOU' worm

NEWS

In less than six hours Thursday, Love spread worldwide. The ILOVEYOU worm struck hundreds of thousands of computers in Asia, Europe and the United States as workers clicked on an email attachment called LOVE-LETTER-FOR-YOU.TXT.vbs. Late Thursday, the worm had turned. Some users reported receiving the same nasty email, but one that substituted "I love you" wording with "very funny joke." But no one was laughing. The Computer Emergency Response Team at Carnegie-Mellon University reported 270,000 computers affected. Computer security firm Network Associates estimated that 1,500 clients -- potentially tens of thousands of computers -- were hit by the wildfire infection, topping by half the number of clients hit by the massive Melissa virus last year. For all that, the worm amounted to not much more than a glorified Melissa virus with a sprinkling of several other virus "technologies" that have afflicted users in the past 12 months, said David Chess, staff research member of IBM's T.J. Watson Research Centre. "It's certainly not a tour-de-force of programming," he said. "It just sort of shows how simple it is to write these sorts of things."

Spread the love Richard M. Smith, the programmer who helped nab the author of the 1999 Melissa virus, said he was amazed by how fast the ILOVEYOU email worm was spreading. "It's so enticing. You get a message that says, 'I love you' and you really want to open up that attachment to see what's going on." Simple but effective. Free emailbox provider MailZone.net found more than 11,000 infected emails Thursday after it started scanning for the virus in messages entering its system. Trend Micro's HouseCall Web-based virus scanner found more than one-fifth of all computers that used the service -- more than 1,000 machines -- had copies of the worm, with each PC having an average of 600 infected files. With a year's worth of experience, the public should know better than to click on unknown attached files, said David Perry, spokesman for anti-virus software maker Trend Micro. "Why did people vote for Nixon twice? Or Clinton? They just don't learn," he said.

But clicking on such attachments is not always an unreasonable choice. Just ask Steven McGhie. The director of Internet business development for Talk2.com of Salt Lake City, McGhie used Microsoft Outlook from a San Francisco hotel room on Thursday to get his morning email. Among the handful of messages was one from his brother with "ILOVEYOU" in the subject line. "He sends me a lot of humour, so I opened it and immediately my system started chugging," said McGhie. Initially, the businessman wondered what was going on. Within moments, however, he received several duplicate messages from his brother. There was also a message from one of Talk2.com's system administrators about the virus. By then, McGhie's computer was already generating messages to everyone in his contact list. He phoned the system admininstrator, who told him to immediately unplug his phone line. Only three minutes had passed since he'd logged on, but the virus had generated close to 600 emails. Most of them were sitting in his outbox when McGhie pulled the plug, but roughly 50 had been sent. McGhie said he had no idea how his brother had received the email worm.

ILOVEYOU hates multimedia PCs infected with the worm receive a double whammy. First, as soon as a user opens the worm file (usually by double-clicking), the malicious code accesses the Outlook address book and sends a copy of itself to every entry. As McGhie witnessed, generating an extreme number of messages takes almost no time. Second, the worm copies itself into every script file and several multimedia files as well, essentially deleting their previous contents. Images (jpg and jpeg), Visual Basic scripts (vbs and vbe) and Java (je and jse) will all be deleted by the file. Music files (mp3 and mp2) are hidden and a file of the same name -- containing the worm's script and a .vbs file extension -- put in its place. The worm also infects files on networked and mapped drives as well as sending itself to people who join a chat room with an infected member. Finally, the virus will attempt to contact one of four Web sites in the Philippines that have a file called WIN-BUGSFIX.exe prepared for download. Those sites have since been taken offline by the Internet service provider who inadvertently hosted them.

What makes Love tick? The key to ILOVEYOU is a macro language for the Windows operating system known as Visual Basic Script. For computers that have the scripting language turned on -- the default Microsoft setting for Windows 98 -- VBS can allow access to almost any system function: Copying, deleting and changing files are all possible. Rob Rosenberger, editor of the Computer Virus Myths Homepage, believes Microsoft should have taken the ability to run such scripts out of Outlook a long time ago. "Why should people need to run scripts in email?" he asked, exasperated. "This should have been dealt with a long time ago.

Virus hunter Smith agreed with such simple changes to Microsoft software. "I think we need to de-tune Windows and make it not so powerful," he said. "Most people don't need VB scripting and never use it. What it seems to be used for most is writing computer viruses." Users, who want to take matters into their own hands and disable the scripting host, can do so by going to Control Panels > Add/Remove Programs > Windows Settings > Accessories and unchecking the selection of the same name. Not that Smith blames Microsoft. "It's sort of a corporate culture issue. When you're making hammers, everything looks like a nail. Programmers think everything in the world needs to be programmable." Microsoft has been reluctant to make any changes to its software, he added. "Macro viruses in Word were discovered in 1995. In Word 2000, there was finally a solution to eliminate the problem, but it took four years. I think that's too long when we're all connected on the Internet."

This is being touted as the most dangerous virus since the Melissa virus last year.

Go to the TalkBack forums to say your piece and read others thoughts and brushes with the ILOVEYOU virus. The Internet and email make it easy for dark forces to distribute damaging software viruses. Tony Westbrook explains how within a day the whole world had got its guard up for the ILOVEYOU virus. Go to AnchorDesk UK for the news comment. What do you think? Tell the Mailroom. And read what others have said. Take me to the Melissa Virus special Take me to the Virus Workshop Take me to the World's most lethal virus: ILOVEYOU roundup

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

4 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

13 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

21 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

23 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

23 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by via Facebook on MPs urge ISPs to take down terrorist material

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by via Facebook on MPs urge ISPs to take down terrorist material