This Valentine's Day virus is Vbs/san by the author of the virus, because the virus is able to set IE's starting page as a Spanish site, which is much like Vbs/san.
The virus hides itself in an HTML file, encrypts its own code using a Vbscript.encode method, and exploits a vulnerability called "Scriptlet.Typelib".
When the virus code is executed, it copies itself to the C:windowsstart Menuprogramsstartup
Loveday14-b.hta, if the current version of Windows is a Spanish version, will the virus copy itself to the corresponding c:windowsmen? Inicioprogramasinicioloveday14-b.hta under the Windowssystem directory at the same time
Create a file main.html.
When the system restarts, Loveday14-b.hta is executed and displays a message box with the following contents, titled
MSDOS. Exe:
The virus sends itself to all the addresses in the Outlook Address Book, the subject of the message is empty, and the message body is an HTML-formatted file with the virus code hidden.
The virus also attempted to send mail messages to random mobile phones that belonged to a Spanish telecoms provider.
The contents of the message are as follows:
Topic: "Feliz san Valentin"
Message body: Feliz San Valentin. Por favor Visita "(followed by a link to a Spanish
website, infected by the virus author.)
The virus also tries to send itself through MIRC in the form of "main.html".
If the current date is 8,14,23, or 29, the virus overwrites all files on the user C disk with Spanish text, and the overwritten file adds one on the basis of keeping the original file name. TXT extension. (for example, the Command.com file under the original C disk will become Comand.com.txt).
These overwritten files contain the following text:
Hola, me llamo Onel2 y voy a utilizar tus archivos para declararle mi amor
A Davinia, La Chica mas Guapa del Mundo.
Feliz San Valentin Davinia. Eres la Mas bonita y la Mas simpatica.
Todos Los Dias a todas horas pienso en ti y cada segundo que no te veo
Es un infierno.
Quieres salir Conmigo?
En Cuanto a ti usuario, Debo decirte que tus
No han sido contaminados por un virus,
Sino sacralizados por el amor que siento, por.
Some of the hidden parts of the code are as follows:
"Que cosa mas Tonta".
"Loveday14 by Onel2 Melilla, Espa 馻"
"Feliz San Valentin Davinia"