ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Old-school worm loves Windows applications

Munir Kotadia ZDNet.co.uk

Published: 07 Jul 2004 17:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest variant of the Lovgate worm scans PCs for executable files and then renames them, a tactic used by viruses from a much older generation, according to antivirus companies.

The Lovgate worm first appeared in February 2003 and has since mutated many times. The most recent versions of the worm -- Lovgate.AE and Lovgate.AH -- were discovered on Sunday. They spread by emailing themselves to addresses found on an infected machine and then open a "back door" to give control of the infected system to an attacker. Finally, the worms scan for vulnerable PCs connected to the infected system's local network -- using the same Windows vulnerability exploited by the MSBlast worm almost a year ago.

The most important difference is the worm's destructive nature. Although the latest Lovgate worm does not delete any user data -- such as documents or spreadsheets -- it replaces executable files (with the .exe extension) on the local hard drive with further copies of itself. This process can leave an infected computer effectively useless because it is unable to run any applications.

Carole Theriault, security consultant at antivirus firm Sophos, said the latest Lovgates are "ancient-style viruses" because they are so destructive.

"Five years ago this was the main way viruses spread -- they got in a system and changed everything, leaving the victim with a useless piece of kit that needed to be restored using a back-up," said Theriault.

Finnish antivirus firm F-Secure warned that Lovgate is capable of destroying most of the executable files on an infected computer.

"The virus might do this renaming operation to hundreds of .exe files in one go. The end result is that instead of finding one or two infected files, the user will find masses of them. With Lovgate, this is normal," the company reported on its labs Web log.

Antivirus firm McAfee's Emergency Response Team increased the threat level of the new Lovgate variants to "Medium" after discovering more than 100 samples of the worm within the first 24 hours of its discovery.

As ever, users are advised not to open email attachments unless they are absolutely sure they are safe and to ensure Windows and other applications are kept up to date with the latest patches.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
86 out of 180 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

IT Technician, Cambridge (9m FTC)

What we are looking for from the IT Technician: Essential - To have experience in assisting end users in questions and problems concerning general ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Recently voted the Top Place to Work in IT we are currently seeking talented Technical Support Engineers to join our exciting new Connected Learning ...

Pembrokeshire - WIN PCS - 6 Month Contract

Huxley Associates currently possesses an immediate requirement for a WIN PCS Administrator for an initial 6 month contract. It is essential that you ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment