ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Lovgate worm starts to spread

Graham Hayday Silicon.com

Published: 24 Feb 2003 16:49 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus vendors are warning internet users to look out for yet another worm -- the second to strike this month.

Called Lovgate, the worm has three variants (A, B and C), and is slightly more difficult to spot than the earlier "Catherine Zeta Jones" malware, as emails carrying it come with random subject lines and contain attachments with a range of file names.

From the copies so far intercepted, the email body text may contain the words, "I'll try to reply as soon as possible. Take a look to the attachment and send me your opinion!"

The file attachment is written in Microsoft Visual C/C++ and is compressed using ASPack and is 78,848 bytes in size, according to antivirus specialist MessageLabs. Attachment file names may include: BILLGT.EXE, CARD.EXE, DOCS.EXE, FUN.EXE, HAMSTER.EXE, HUMOR.EXE, IMAGES.EXE, JOKE.EXE, MIDSONG.EXE, NEWS_DOC.EXE, PICS.EXE, PSPGAME.EXE, S3MSONG.EXE, SEARCHURL.EXE, SETUP.EXE, TAMAGOTXI.EXE.

According to the company's initial analysis, Lovgate is a mass-mailing worm that incorporates an SMTP engine and a backdoor component.

In a statement released this morning, MessageLabs said that although the virus contains an SMTP engine, it attempts to connect to a host on the Internet (SMTP.163.COM) to deliver its email. When activated, the virus may try to reply to any emails it finds in the recipient's inbox, attaching itself to the email.

MessageLabs added that it also appears to be able to harvest passwords from the recipient's machine, which may then be emailed to a number of email contacts.

According to Trend Micro, a notification message is sent to two addresses: 54love@fescomail.net and hacker117@163.com. This notification message is present in both WORM_LOVGATE.B and WORM_LOVGATE.C, suggesting that both variants have been created by the same virus author. The two email addresses belong to a network in Beijing, China.

The backdoor component may open TCP port 10168, allowing the machine to be controlled remotely. The worm may also have the ability to spread via various network shares.

The worm has affected around 300 users to date, most of whom were based in Asia, according to Trend Micro. MessageLabs says that it was first seen in the US, and is most active in Belgium, South Africa and the US.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
50 out of 95 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Websphere Developer - Message Broker/MQ - West Midlands

Java / Websphere / Message Broker / SOAP / Webservices. The key technical skills they are looking for are Websphere Message Broker (WMB) as well as ...

Websphere Message Broker Consultant

My client, a financial insitution requires a Websphere Message Broker consultant to join their programme. Ideal candidates will have excellent ...

Embedded C / RTOS / Auto / Micro / South East 6 months

Embedded C developer required for my automotive client in the South East for an initial 6-month contract. The successful candidate will have ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains