Detections Included in this EXTRA.DAT - May 10, 2000 - McAfee AVERT
-------------------------------------------------------------------
VBS/LoveLetter.worm
This is a generic driver that detects all known variants of this worm, 29 as of the date of this posting. This also covers detection of the HTML file dropped by the VBS worm.

VBS/LoveLetter.pws
This driver detects and removes the password stealing trojan that the VBS worm tries to download from the Internet. It is important to note that the trojan has now been removed from the Internet and is no longer available for download by the VBS worm.

VBS/LoveLetter.ini
This driver detects the mIRC script.ini file dropped by the VBS worm.

UNIX/LoveLetter.worm
This driver detects a version on LoveLetter that someone 'ported' to UNIX shell script. This has not been seen in the wild at this point but the source has been published on the Internet so we have included detection for it, in the event someone tries to use it.

VBS/FriendMess
This driver detects another VBS worm that uses some of the e-mail transmission code from LoveLetter, and appeared shortly after the outbreak of LoveLetter.

New VBS
This driver is a heuristic driver that detects scripts that use email to send themselves to other systems. This is included as a failsafe to detect any strange variants of LoveLetter that may be so different as to escape the generic detection of thge VBS/LoveLetter.worm driver.
NOTE1 - VBS/FriendMess was initially detected by this driver.
NOTE2 - In order to facilitate older scan engines, there is an additional driver for NEW VBS which will help detect these script viruses however the minimum required engine is 4.0.35 for full detection capability.

----------------------------------------------------
Neil Cowie - Senior Virus Research Engineer
McAfee AVERT - A division of Network Associates Inc.