Virus Characteristics
VBS/Valentin@MM is detected as "New Script" with heuristics enabled using the 4120 engine. This virus contains a
destructive payload, instructions to
send itself via Outlook email and also
send messages to cell phones.
This virus is believed to have been created by the author of VBS/San@M.It also sets the Internet Explorer start page to a Spanish website, similar to VBS/San@M.
The virus is embedded in an HTML file, uses the Vbscript.Encode method to partially encrypt its code, and makes use of the, so called, "Scriptlet.TypeLib" vulnerability.
When the viral code is executed, it copies itself to the StartUp folder, "c:\WINDOWS\Start Menu\Programs\Startup\loveday14-b.hta". If the Spanish version of Windows is detected, it copies itself to the corresponding Startup folder, "c:\WINDOWS\Menú Inicio\Programas\Inicio\loveday14-b.hta".
The file "main.html" is created in the WINDOWS SYSTEM directory.
The virus sends itself to all recipients found in the Outlook Address Book. The subject line of the message is left empty and there is no attachment. The e-mail message body contains the embedded virus code, in HTML format.
The virus attempts to send e-mail messages to random mobile-phone addresses of a Spanish telecom provider. These messages contain the following information:
Subject: "Feliz san valentin"
Body: "Feliz san valentin. Por favor visita" (followed by a link to a Spanish website, infected by the virus author.)
It virus attempts to use the mIRC Internet Relay Chat client to send itself, as "main.html", to other IRC users.
If the current day is 8, 14, 23, or 29, the virus attempts to overwrite all files on the C: drive with Spanish text. The overwritten files contain the original file name with the extension .TXT (ie. C:\COMMAND.COM becomes C:\COMMAND.COM.TXT)
These overwritten files contain the text:
Hola, me llamo Onel2 y voy a utilizar tus archivos para declararle mi amor
a Davinia, la chica mas guapa del mundo.
Feliz san Valentin Davinia. Eres la mas bonita y la mas simpatica.
Todos los dias a todas horas pienso en ti y cada segundo que no te veo
es un infierno.
Quieres salir conmigo?
En cuanto a ti usuario, debo decirte que tus ficheros
no han sido contaminados por un virus,
sino sacralizados por el amor que siento por Davinia.
Some visible parts of the code are:
"Que cosa mas tonta".
"loveday14 by Onel2 Melilla, España"
"feliz san valentin davinia"