# ILOVEYOU

**URL:** <https://boards.straightdope.com/t/iloveyou/18563>\
**Category:** Factual Questions\
**Created:** [May 4, 2000, 3:51pm UTC](https://boards.straightdope.com/t/iloveyou/18563 "2000-05-04T15:51:11Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![coosa](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@coosa](https://boards.straightdope.com/u/coosa)\
**Post date:** [May 6, 2000, 8:51pm UTC](https://boards.straightdope.com/t/iloveyou/18563/21 "2000-05-06T20:51:55Z")

</div>

I posted something similar over in the Pit, but thought I’d post a quick defense here. Please, everyone who opened one of those attachments isn’t ‘stupid’. A friend of mine received an e-mail from her daughter’s e-mail addy. The ‘ILOVEYOU’ was attached. With Mother’s Day coming up, my friend assumed this was something sweet and loving from her daughter, and opened it.

According to McAfee, there is also a variant that claims to be a virus update from Symantec! I believe that when I checked this morning, there were 8 variants listed.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [May 7, 2000, 1:23am UTC](https://boards.straightdope.com/t/iloveyou/18563/22 "2000-05-07T01:23:25Z")

</div>

> [@](#):
>
> \*\*  
> _STUPID STUPID USERS!_ What were you thinking? This is just the same as the melissa virus! Delete strange attachments, do not run or view them! E-mail the person asking them what it was!
> 
> \*\*

Considering Outlook runs the .vbs file in the preview pane and the mail will come from someone you know (it uses address books) its not the user’s fault, for the most part. Their only fault is using Outlook, it is not secure and MS targets new computer users with their advertising.

---

<div class="post-metadata">

**Author:** ![Kyberneticist](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@Kyberneticist](https://boards.straightdope.com/u/Kyberneticist)\
**Post date:** [May 7, 2000, 3:49pm UTC](https://boards.straightdope.com/t/iloveyou/18563/23 "2000-05-07T15:49:01Z")

</div>

Really? Never having used outlook I wouldn’t know, but I imagined the preview pane to be a preview of the attachment.  
Even if an executable comes from a friend I still ask them what it was and where they got it before running it. Some of my friends would forward pretty much anything.

---

<div class="post-metadata">

**Author:** ![yabob](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yabob/32/2821_2.png) [@yabob](https://boards.straightdope.com/u/yabob)\
**Post date:** [May 7, 2000, 5:18pm UTC](https://boards.straightdope.com/t/iloveyou/18563/24 "2000-05-07T17:18:58Z")

</div>

Another contributing factor is MS’s belief that everything has to have a scripting language buried in it somewhere. Hence, you get viruses transmitted by things like word doc’s and excel spread sheets which, to the casual user, seem like read-only things which ought to be “safe”.

I fully understand how such features get proposed - it provides sort of an “ultimate escape hatch” to allow people to do all kinds of stuff you couldn’t explicitly provide functionality for, and probably wouldn’t have thought of in the first place. I’ve made arguments like that myself.

Trouble is, it can be very difficult to keep such a mechanism in desired boundaries, or even define what those boundaries are. For instance, it might be useful for me to be able to provide a word doc for you that is tailored using information obtained by looking at configuration files on your system, rather than having to say “go look at foo.config, and if it says ‘farblesnarb’ do this …” … but giving the word doc access to the file system, even read-only access, may be a bad idea.

If we’re really going to operate in an interconnected environment like this, both OS security and users are going to have to grow up. Something which talks to the outside world, like a mailer or a browser really needs to provide a “playpen” for its attachments to run in, there needs to be a negotiated contract with the attachment concerning the sorts of communication / system access services it needs, and the user should be prepared to have some picture of what this implies (“do you want to let this attachment read files on your machine …?”). Off the top of my head, in the current Windows environment, I would provide “permission aware” DLL’s and a special linkage operation for running things like viewers and helper app’s out of mailers which would keep them from using the normal Windows SDK. They’d run slower, but more securely (“naughty attachment! I didn’t tell you you could write files …”).

---

<div class="post-metadata">

**Author:** ![Una\_Persson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/una_persson/32/346_2.png) [@Una\_Persson](https://boards.straightdope.com/u/Una_Persson)\
**Post date:** [May 7, 2000, 6:03pm UTC](https://boards.straightdope.com/t/iloveyou/18563/25 "2000-05-07T18:03:07Z")

</div>

I’ve heard a lot of people sniff and say the virus code is amatuerish and simple, but in looking at it I think it has several clever points. It showed me some things I could do with VBS that I didn’t know about. In fact, I lifted some of the code to make a couple cool utilities for myself.

And if someone with my limited skills can do that, how many copycats will there be?

I agree with all of the following points, however:

1. Don’t open strange attachments, etc.
2. Windows and Outlook have huge security holes, etc.
3. The disruption caused by it was awful, and the creator was lame. At least they could have pretended to have a Cause or something, not “i hate go to school”. Yup, no way are you a loser.

---

<div class="post-metadata">

**Author:** ![Elthia](https://avatars.discourse-cdn.com/v4/letter/e/e274bd/32.png) [@Elthia](https://boards.straightdope.com/u/Elthia)\
**Post date:** [May 8, 2000, 4:20am UTC](https://boards.straightdope.com/t/iloveyou/18563/26 "2000-05-08T04:20:45Z")

</div>

> [@](#):
>
> \*\*  
> The other reason viruses for Windows are so popular is that Windows allows programs to do almost whatever they want with the system. Time and again I will walk up to a public

Which is why linux/unix/etc rocks. _grin_

> [@](#):
>
> _STUPID STUPID USERS!_ What were you thinking? This is just the same as the melissa virus! Delete strange attachments, do not run or view them! E-mail the person asking them what it was!  
> Heck, I delete all my spam/strange mail in pine, just so that Netscape doesn’t parse the cgi/cookie requests and encourage spammers.  
> Ok. Done ranting.  
> \*\*

Excellent advise in any case, but rarely followed through on except by paranoid nutcases like us. _innocent look_

I got this straight off the bugtraq archives, I’m posting it in its entirety despite it being a bit long - those who understand it can talk about it, those who don’t can ask about it, but information is always good to have.

And 'cause I’m too lazy to type the whole explanation out.

-Elthia

* * *

“ILOVEYOU” virus analysis

Forum: Denial of service attack against tcpdump  
Date: May 04, 17:22  
From: Steve Wolfe \<[telomere@INCONNECT.COM](mailto:telomere@INCONNECT.COM)\>

## A brief analysis of the “iloveyou” virus that’s now hitting quite a few people…

## Disclaimer: This is information provided in good-faith, with the intent to assist those afflicted by the virus. I am not responsible for any consequence of reading or using this information.

“iloveyou” is a virus/trojan that is spreading very prolifically, and  
creating a headache for many IT employees. It is written in VBScript, and  
proliferates itself via email.  
Introduction. The virus proliferates itself via email, sending letters  
with the subject “ILOVEYOU”, and in the body, “kindly check the attached  
LOVELETTER coming from me.”

```
  Attached is a VBScript file called "I-LOVE-YOU.TXT.vbs". The

```

capitalization is apparently an attempt to fool users if they are not  
looking carefully, upon seeing the “.TXT”, they think the file is a (safe)  
text file, and run it.

Once executed, the script does the following:

1. If the key “HKEY\_CURRENT\_USER\Software\Microsoft\Windows Scripting  
Host\Settings\Timeout” is set to a positive number in the registry, it is  
set to zero. If it is not present, it is not affected.

2. The VBScript then saves a copy of itself to:

3. Sets the appropriate registry entries to start it on boot:

HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32  
=\> (b)  
HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Wi  
n32DLL =\> (a)

1. Changes the MSIE home page to a presumably malicious URL. If the file  
“WinFAT32.exe” exists, then it sets the startup page (contained in the  
registry setting (HKCU\Software\Microsoft\Internet Explorer\Main\Start  
Page) to one of the following URL’s:

[http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw65873](http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw65873)  
45gvsdf7679njbvYT/WIN-BUGSFIX.exe  
[http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwerWe546786](http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwerWe546786)  
324hjk4jnHHGbvbmKLJKjhkqj4w/WIN-BUGSFIX.exe  
[http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdQZnmPOhfgE](http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdQZnmPOhfgE)  
R67b3Vbvg/WIN-BUGSFIX.exe  
[http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwe](http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwe)  
rasdjhPhjasfdglkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/WIN-BUGSFIX.exe

I haven’t looked at those executables, but persumably, they are also of  
malicious intent. The sites above were not reachable, I assume that the  
onslaught has brought their web servers to their knees, or the  
administrators have simply shut them down/blocked traffic.

1. If the “WIN-BUGSFIX.exe” file exists, it then sets it to run at boot:

HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BUGSFI  
X = \> (download directory)\win-bugsfix.exe

and also sets the MSIE startup page to about:blank (a blank page).

1. It then prints out HTML, containing these messages:

This HTML file need ActiveX Control  
To Enable to read this HTML file

- Please press #-#YES#-# button to Enable ActiveX

1. The ActiveX then sets the registry entries to make it run at boot, as  
in step #3, and writes the files as in step 2.

2. The virus spreads itself. It opens up a MAPI connection to your  
Outlook address list, and sends a copy of itself to each of the entries.

3. Enumerates disk drives and infects files.

* * *

Removal

```
Removing the virus is easy enough, but as another author said ("The

```

Pope"), it is painful, and if you have useful VBScript, WSH or other files  
of similar nature (listed below), you may have already lost very valuable  
data. The steps are:

1. Remove the registry entries

HKEY\_CURRENT\_USER\Software\Microsoft\Windows Scripting  
Host\Settings\Timeout  
HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32  
HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Wi  
n32DLL  
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page  
remove _all_ instance of the following files:

LOVE-LETTER-FOR-YOU.HTM  
\*.vbs  
\*.vbs  
\*.vbe  
\*.js  
\*.jse  
\*.css  
\*.wsh  
\*.sct  
\*.hta

Find hidden files of .mp2 and .mp3 extensions, and remove the “hidden”  
bit.

It is also a good idea to clear the “documents” folder.

Now, for .jpg and .jpeg files… technically, they should be removed.  
However, since jpg’s are not executable, I do not see how they could affect  
anything, but then again, I’m not all-knowing. Also, they did not appear  
to have been infected on the machine I looked at, but that doesn’t mean  
that they won’t be infected on your machine. The safest bet is to remove  
them as well.

* * *

Prevention:

Delete the email if you receive it, and are using one of the MS Outlook  
programs, do not open it if you receive it via IRC.

* * *

Overall comments

This virus doesn’t really represent any new technology or technique, just  
a mix of some commonly-known methods. The single semi-unique aspect is  
using VBScript. By using unique capitalization of files  
(LOVE-LETTER-FOR-YOU.TXT.vbs), it is possible to make many people think  
that it’s just a regular text file.

As to the origin of the virus, a commen section in the code claims  
creation by “spyder”, giving an email address, what appears to be a  
company, and “Manila,Philippines”. Whether the author would actually put a  
real email address and location is questionable.  
steve

---

<div class="post-metadata">

**Author:** ![JoeyBlades](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@JoeyBlades](https://boards.straightdope.com/u/JoeyBlades)\
**Post date:** [May 8, 2000, 3:04pm UTC](https://boards.straightdope.com/t/iloveyou/18563/27 "2000-05-08T15:04:26Z")

</div>

Kyberneticist wrote:

> [@](#):
>
> Hm. On the other hand, Macs aren’t terribly secure either (although OSX may be changing that). A quick net search indicates estimates of between two and three hundred Mac viruses.

According to the Macintosh Virus FAQ:  
[http://www.icsa.net/html/communities/antivirus/faqs/macfaq.shtml](http://www.icsa.net/html/communities/antivirus/faqs/macfaq.shtml)

> [@](#):
>
> # 6.0 How many viruses affect the Macintosh?
> 
> There are around 40 Mac-specific viruses and related threats.

SPOOFE Bo Diddly writes:

> [@](#):
>
> ::sigh::… Mac lovers… always missing the painfully obvious…
> 
> The point of a computer virus is to cause as much damage as possible. The reason nobody makes a virus for a Mac is 'cuz nobody WANTS to.

Who’s missing what??? It doesn’t matter **WHY** the Mac is less susceptible. It only matters, to me anyway, that it **IS**!!!

However, your assessment is not entirely correct. Desire and targetability are not the only reasons Mac viruses are not popular. Viruses for the Mac are much more difficult to propagate because the OS was designed to guard against them.

> [@](#):
>
> That’s like declaring war with Antarctica.

More like Switzerland, I’d say.  
Back on topic…

I remember, many years ago, when I first started hearing about email viruses. The conventional wisdom, at the time, was that all email viruses were hoaxes because no one would be stupid enough to build a mail program with an embedded programming language… Microsoft, once again, proved that they were up to the challenge and did what the experts said shouldn’t be done…

For me, this clearly falls into the realm of “what were they thinking?!”. The time is really ripe for this kind of attack, because so many computer users now have MS Outlook pre-installed and most average users don’t know how dangerous that software really is… after all, if you can’t trust Microsoft to look out for your best interest, who can you trust?

I predict, now that so many people have seen how easy it is to wreak this kind of havoc, there will be a continuing outbreak of cut & paste terrorism.

---

<div class="post-metadata">

**Author:** ![Whack-a-Mole](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/whack-a-mole/32/141_2.png) [@Whack-a-Mole](https://boards.straightdope.com/u/Whack-a-Mole)\
**Post date:** [May 8, 2000, 3:19pm UTC](https://boards.straightdope.com/t/iloveyou/18563/28 "2000-05-08T15:19:41Z")

</div>

The I Love You Virus has the following effects:

1. Will mail itself to everyone in your address list if you use Outlook.

2. Changes the homepage of your browser to an ISP in the Phillipines where it would download password capture software to your pc (the pages in the Phillipines have been shutdown by that ISP so this no longer works).

3. The program deletes all files with the following extensions and creates a file with the same name but with a VBS extension in its place: **vbs, vbe, js, jse, css, wsh, sct, hta, jpg, jpeg** Also, all MP3 and MP2 files will be hidden and a new file with the same name but a VBS (instead of MP3) extension will be created.

Of the above JPG are probably the most common (JPG files are pictures).

Some of the new variants have slightly different payloads but I’m not sure of the differences between each one. I do know that the relatively rare Mother’s Day variant will delete INI files from your PC which can very possibly force the user to rebuild their PC from scratch (depending on how good the user has been with backing up system files).

---

<div class="post-metadata">

**Author:** ![Kyberneticist](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@Kyberneticist](https://boards.straightdope.com/u/Kyberneticist)\
**Post date:** [May 8, 2000, 4:10pm UTC](https://boards.straightdope.com/t/iloveyou/18563/29 "2000-05-08T16:10:47Z")

</div>

JoeyBlades wrote:

> [@](#):
>
> According to the Macintosh Virus FAQ:  
> [http://www.icsa.net/html/communities/antivirus/faqs/macfaq.shtml](http://www.icsa.net/html/communities/antivirus/faqs/macfaq.shtml)  
> 6.0 How many viruses affect the Macintosh?  
> ===========================================
> 
> There are around 40 Mac-specific viruses and related threats.

That’s a little bizaare, since when I counted the ones listed in that FAQ, I came up with 54. Furthermore, as the FAQ notes, that is only major strains, not variants (and most viruses have many variants which accounts for the high Windows number, particularly with virus toolkits)

> [@](#):
>
> However, your assessment is not entirely correct. Desire and targetability are not the only reasons Mac viruses are not popular. Viruses for the Mac are much more difficult to propagate because the OS was designed to guard against them.

How was MacOS designed to guard against viruses? I am a little curious. From the fiddling I’ve done with it, it is, like Windows, very much a single user type platform. Since WinNT actually has some concept of file rights and security, one claim it was designed to guard against viruses too, but that was hardly it’s primary function.  
In any case, I wrote a simple virus for the Power architecture in our Assembly class. I didn’t see much that made it harder. (except for the pain of having to do in 5 instructions what x86 CISC would allow us to do in 2)

BTW, I said two or three hundred after reading here:  
[http://emt.doit.wisc.edu/macvir/macvir.(06](http://emt.doit.wisc.edu/macvir/macvir.(06)).html

I tried checking Apple’s site for more info, but their search engine, as usual, was crap. No real FAQs on viruses that I could find.  
Reminded me of the time I had to get info on what the different bomb numbers meant by visiting a Mac fan website since there was nothing on Apple’s.  
Well, OSX is BSD from what I here, so we can hope for a change.  
At the moment, I love the PowerPCs… when running Yellow Dog Linux.

---

<div class="post-metadata">

**Author:** ![hardcore](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@hardcore](https://boards.straightdope.com/u/hardcore)\
**Post date:** [May 8, 2000, 4:19pm UTC](https://boards.straightdope.com/t/iloveyou/18563/30 "2000-05-08T16:19:01Z")

</div>

JoeyBlades:

> [@](#):
>
> Microsoft, once again, proved that they were up to the challenge and did what the experts said shouldn’t be done…

What is it that you think Microsoft shouldn’t have done? Design an email program that will run attachments if you double-click them? That is the only way this particular virus will spread.

---

<div class="post-metadata">

**Author:** ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)\
**Post date:** [May 8, 2000, 6:26pm UTC](https://boards.straightdope.com/t/iloveyou/18563/31 "2000-05-08T18:26:25Z")

</div>

> [@](#):
>
> posted by hardcore:  
> What is it that you think Microsoft shouldn’t have done? Design an email program that will run attachments if you double-click them? That is the only way this particular virus will spread.

harcore, your statement is incorrect. Please verify your statements before posting, because with computer viruses, giving false information can have unintended consequences.  
From an article in Computerworld, [“Love” virus includes password-stealing Trojan Horse, By Ann Harrison, 05/04/2000](http://www.computerworld.com/home/print.nsf/all/000504DC02):

> [@](#):
>
> The virus targets Microsoft’s Outlook e-mail program, automatically sending messages with the virus to everyone in the address book of the infected user. Microsoft said Outlook users can protect themselves simply by not opening the messages.
> 
> But for users who have both Outlook and a companion product called Windows Scripting Host, simply previewing the message is enough to activate the virus, CERT (_Computer Emergency Response Team_) reported. “Advice to avoid clicking on unsolicited mail doesn’t help in this case, though it does help users of e-mail programs other than Outlook,” CERT said in a statement.

---

<div class="post-metadata">

**Author:** ![Kyberneticist](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@Kyberneticist](https://boards.straightdope.com/u/Kyberneticist)\
**Post date:** [May 8, 2000, 7:08pm UTC](https://boards.straightdope.com/t/iloveyou/18563/32 "2000-05-08T19:08:55Z")

</div>

I must confess that since I haven’t used windows in a while I am not that qualified to speak on this, but I have been reading up on .vbs files and Windows Scripting Host.  
[http://msdn.microsoft.com/library/periodic/period98/cutting0698.htm](http://msdn.microsoft.com/library/periodic/period98/cutting0698.htm)

It appears the WSH module is necessary to run the .vbs file, it is not at all clear that running it will happen accidently.  
This article still claims it will take a double-click to run a .vbs file. Previewing an attachment normally launches some application that tries to do something with it. That is a more active role on the user’s part then simply clicking on an e-mail.  
Again, the question is why people would even touch a .vbs, or any other attachment aside from a text or image file without adequate explanation of what it does.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [May 8, 2000, 7:11pm UTC](https://boards.straightdope.com/t/iloveyou/18563/33 "2000-05-08T19:11:30Z")

</div>

I am somewhat confused… I use Outlook Express 5. In Tools/options/security I can set it to “internet” or “restricted” (this seems to work in conjunction with IE5 settings). If I set it to “restricted” will it prevent it from running VBS attachments in preview mode?

I have never received a VBS attachment so I do not know what it does. I know I can see JPG and GIF graphics in preview mode but in my experience all other attachments need to be opened, including TIF graphics.

Can anyone clarify this for me? Word and Excel have a setting that will preven running macros. I should thing OE would have a similar security feature.

---

<div class="post-metadata">

**Author:** ![hardcore](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@hardcore](https://boards.straightdope.com/u/hardcore)\
**Post date:** [May 8, 2000, 7:28pm UTC](https://boards.straightdope.com/t/iloveyou/18563/34 "2000-05-08T19:28:48Z")

</div>

Arnold, I posted a reply to you in the other thread that you posted this same response in. Basically, you need some evidence to back up your theory. All of my experiments refute your assertion that vbs files will run automatically.

---

<div class="post-metadata">

**Author:** ![hardcore](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@hardcore](https://boards.straightdope.com/u/hardcore)\
**Post date:** [May 9, 2000, 9:27am UTC](https://boards.straightdope.com/t/iloveyou/18563/35 "2000-05-09T09:27:45Z")

</div>

sailor, OE 5.0 won’t run vbs attachments in the preview panel regardless of your security settings.

---

<div class="post-metadata">

**Author:** ![JoeyBlades](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@JoeyBlades](https://boards.straightdope.com/u/JoeyBlades)\
**Post date:** [May 9, 2000, 2:54pm UTC](https://boards.straightdope.com/t/iloveyou/18563/36 "2000-05-09T14:54:47Z")

</div>

Kyberneticist wrote:

> [@](#):
>
> That’s a little bizaare, since when I counted the ones listed in that FAQ, I came up with 54

Some of those listed are trojan horses. I don’t put trojan horses in the same class as viruses.

[quote]

Furthermore, as the FAQ notes, that is only major strains, not variants (and most viruses have many variants which accounts for the high Windows number, particularly with virus toolkits)

[quote]

In the Mac world, almost all of the ‘variants’ are identical except for the name of the resource. Few of them are true variants, in the sense that the virus code has been modified.

> [@](#):
>
> How was MacOS designed to guard against viruses?

This is not the ideal place to explain this and I am not the ideal person to explain it. However, suffice it to say that the Macintosh has a very restricted and controlled mechanism for executing code and file I/O. Because of this, antivirus software for the Mac doesn’t need to know about every strain of every virus, it only needs to close all of the back doors, which Disinfectant did more than three years ago.

The Mac OS can’t do anything special to guard against Microsoft macro viruses because Microsoft built in the flexibility and power to let users do practically anything they want.

> [@](#):
>
> In any case, I wrote a simple virus for the Power architecture in our Assembly class.

You developed this virus on the Mac? If so, I’m impressed. I have a hard enough time getting the Mac INIT and VBL mechanisms to do what they were designed for, much less tricky stuff like virus propagation. As for the PowerPC architecture, I don’t think it has any mechanisms to guard against virus attacks itself.

> [@](#):
>
> Reminded me of the time I had to get info on what the different bomb numbers meant by visiting a Mac fan website since there was nothing on Apple’s.

You probably just didn’t know where to look. Error code listings have been available on the Apple developer sites since the introduction of the Lisa (precursor to the Mac).  
hardcore wrote:

> [@](#):
>
> Basically, you need some evidence to back up your theory. All of my experiments refute your assertion that vbs files will run automatically.

This is a very reckless way to live your life, my son. A number of reputable virus experts have said that the vbs files can run automatically if you have “Windows Scripting Host” running with MS Outlook and possibly “Active Scripting” in Internet Explorer. This has been verified already by the CERT at Carnegie Mellon Software Engineering Institute. Sorry, but I find them to be infinitely more credible…

---

<div class="post-metadata">

**Author:** ![hardcore](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@hardcore](https://boards.straightdope.com/u/hardcore)\
**Post date:** [May 9, 2000, 4:04pm UTC](https://boards.straightdope.com/t/iloveyou/18563/37 "2000-05-09T16:04:25Z")

</div>

I have all that installed on several computers. Go to the CERT site and see if you can find anything there that backs up your assertion. I can’t.

---

<div class="post-metadata">

**Author:** ![swisemankcmo](https://avatars.discourse-cdn.com/v4/letter/s/a8b319/32.png) [@swisemankcmo](https://boards.straightdope.com/u/swisemankcmo)\
**Post date:** [May 9, 2000, 5:26pm UTC](https://boards.straightdope.com/t/iloveyou/18563/38 "2000-05-09T17:26:34Z")

</div>

> **[Technology News](https://www.cnet.com/news/?tag=st)**
>
> CNET news editors and reporters provide top technology news, with investigative reporting and in-depth coverage of tech issues and events.

If any of THAT is true…

---

<div class="post-metadata">

**Author:** ![JoeyBlades](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@JoeyBlades](https://boards.straightdope.com/u/JoeyBlades)\
**Post date:** [May 9, 2000, 6:53pm UTC](https://boards.straightdope.com/t/iloveyou/18563/39 "2000-05-09T18:53:25Z")

</div>

OK, fair enough. They never use the words “automatic launch” however it is implied by

(1) Their instructions to disable “Windows Scripting Host” and “Active Scripting”.

(2) They reference the “Sophos” site which does indicate the execution is automatic.  
I’ve seen a couple of other trusted sites that claim that the virus can launch automatically. Plus, a number of sys admins at my company claim that they were infected, even though they never opened the message…  
However, Microsoft’s official position is:

> [@](#):
>
> It’s important to note that the virus payload cannot run by itself. In order for it to run, the recipient must open the mail, launch the payload by double-clicking on it, and answer “yes” to a dialogue that warns of the dangers of running untrusted programs.

So now I don’t know who to believe.

---

<div class="post-metadata">

**Author:** ![hardcore](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@hardcore](https://boards.straightdope.com/u/hardcore)\
**Post date:** [May 9, 2000, 6:57pm UTC](https://boards.straightdope.com/t/iloveyou/18563/40 "2000-05-09T18:57:31Z")

</div>

As the cnet article pointed out, the Love virus doesn’t use scripts buried in html, although I’m surprised it didn’t. I briefly mentioned in the other thread on this topic at [http://boards.straightdope.com/sdmb/showthread.php?threadid=23703](http://boards.straightdope.com/sdmb/showthread.php?threadid=23703)  
how this could be done, but I didn’t want to give anybody any ideas.

[Previous page](https://boards.straightdope.com/t/iloveyou/18563.md?page=1)

[Next page](https://boards.straightdope.com/t/iloveyou/18563.md?page=3)
