Hi there
I've discovered a few problems linked to LoveLetter.vbs but can't get rid of it. It's a bit complicated to explain so please bear with me whilst I try to explain the issues...........
Each time I opened Firefox and started to surf, I'd get various other Firefox windows opening with adverts. I scanned with Avast 4.0, AVG, Ad-Ware SE (all 3 are Home Editions) and Spybot S&D. I found nothing with any of these scans including Avast Boot Time Scan. However, I knew something was there as my system was so slow, my desktop photo had been overwritten and I kept getting the adverts opening in other Firefox Windows.
A friend suggested using ClamWIN anti-virus which I did. Whilst using ClamWIN (in Normal XP mode) Avast suddenly found LoveLetter.vbs in C:\Documents and Settings\"My user name"\Local Settings\Temp\clamav-fcd948e599fd513b7fceeb9929cac426d.00000dc0.clamtmp. When I looked in the Avast Chest the file that had been quarantined was called 'script.html'
I ran ClamWin again and again it found LoveLetter.vbs in the same folder but the file name had changed the alpha-numeric string between clamav- and -clamtmp
This continued each time I ran ClamWIN with the alpha-numeric string changing. I also found another version of the file in the Chest called 'comment.html'
At the same time I found some strange files (WHICH I CAN'T DELETE) in C:\Documents and Settings\"My user name"\Local Settings\Temp called 'Perflib_Perfdata_948.dat' and 'Perflib_Perfdata_f5c.dat' etc etc.....
Other strange files in the same folder are '~DF6D7D.tmp' and '~DF8AEA.tmp' etc etc......
I have deleted any files and registry keys associated with LoveLetter.vbs (as suggested in the Avast help pages about Worms etc) and since ran numerous scans finding nothing but I'm still worried that there may be something in the background. Each time I run ClamWIN the LoveLetter.vbs worm is still found by Avast On-Access scanner.
The only applications I've downloaded recently are VEOH and a Windows Media Player that lets you watch streaming TV (which I've now deleted).
I have now deleted ClamWIN, and ran, AVAST, AVG, Ad-Ware SE, Spybot S&D and Zone Alarm scans and found nothing.........however the strange files mentioned above still exist............
SHOULD I BE WORRIED OR NOT?
?.............PLEASE HELP