Content
VBS/Renalo@MM
- Type
- Virus
- SubType
- VBScript worm
- Discovery Date
- 12/26/2002
- Length
- 15,190
- Minimum DAT
- 4241 (01/08/2003)
- Updated DAT
- 4241 (01/08/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 12/31/2002
- Description Modified
- 12/31/2002 12:36 PM (PT)
Tab Navigation
Characteristics
This is a VBScript worm, which requires the Windows Scripting Host in order to run. It is detected as a variant of New Script with macro and script heuristics enabled.
When run, it first displays a message box:

It then sends email to all the users in Windows Outlook address book using MAPI addressing. The email subject is chosen randomly from the following list:
- "Re:"
- "Exciting Photos"
- "Photos XXX"
- "Sensual photos"
- "hi check these super photos"
- "check my exciting photos"
- "look these exciting photos"
- "Please check my photos in beach"
- "Sensual photos single for you "
The worm creates the following registry keys in order to run at Windows start up. It also changes autoexec.bat for the same purpose.
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"System"="C:\Windows\System 32\*.JPEG.vBS"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"WINFT" = "C:\WINNT\NT.JPEG.vBS"
The worm searches the local hard drive for the following peer-to-peer file sharing folders and copies itself to these folders.
- \KaZaA\My Shared Folder\
- \ICQ\shared files\
- \eDonkey2000\incoming\
- \bearshare\shared\
- \Grokster\My Grokster\
- \Morpheus\My Shared Folder\
Symptoms
Presence of the Lorena-te-amo.vbs file and registry keys mentioned above.
Method of Infection
The worm can spread via peer-to-peer network shares and IRC channels.
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- I-Worm.Lorena (AVP)
Characteristics
Characteristics -
This is a VBScript worm, which requires the Windows Scripting Host in order to run. It is detected as a variant of New Script with macro and script heuristics enabled.
When run, it first displays a message box:

It then sends email to all the users in Windows Outlook address book using MAPI addressing. The email subject is chosen randomly from the following list:
- "Re:"
- "Exciting Photos"
- "Photos XXX"
- "Sensual photos"
- "hi check these super photos"
- "check my exciting photos"
- "look these exciting photos"
- "Please check my photos in beach"
- "Sensual photos single for you "
The worm creates the following registry keys in order to run at Windows start up. It also changes autoexec.bat for the same purpose.
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"System"="C:\Windows\System 32\*.JPEG.vBS"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"WINFT" = "C:\WINNT\NT.JPEG.vBS"
The worm searches the local hard drive for the following peer-to-peer file sharing folders and copies itself to these folders.
- \KaZaA\My Shared Folder\
- \ICQ\shared files\
- \eDonkey2000\incoming\
- \bearshare\shared\
- \Grokster\My Grokster\
- \Morpheus\My Shared Folder\
Symptoms
Symptoms -
Presence of the Lorena-te-amo.vbs file and registry keys mentioned above.
Method of Infection
Method of Infection -
The worm can spread via peer-to-peer network shares and IRC channels.
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A