The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

We Build the Best & Repair the Rest! ©

 

Alerts September 2004

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


March 2004 August 2004 November 2004 October 2004 April 2004 July 2004 Virus Alert Calendars May 2004 September 2004 June 2004 January 2004 February 2004 Alerts 2003 Alerts Jan 2004 Alerts Feb 2004 Alerts March 2004 Alerts April 2004 Alerts Top 10 May 2004 Alerts Top10 June 2004 Alerts Top 10 July 2004 Alerts August 2004 Alerts September 2004 Alerts Oct 2004 Alerts November 2004 Alerts December 2004

 

 

 

 

Top 10 malware reported to Sophos in September 2004

Position Last
month
Malware Percentage of reports
1 1 W32/Zafi-B
   30.5%
2 2 W32/Netsky-P
   26.7%
3 4 W32/Netsky-D
   6.1%
4 5 W32/Netsky-Z
   5.5%
5 6 W32/Bagle-AA
   3.8%
6 3 W32/MyDoom-O
   3.6%
7 7 W32/Netsky-B
   3.5%
8 9 W32/Netsky-Q
   2.7%
9 8 W32/Lovgate-V
   2.6%
10 10 W32/Netsky-C
   2.0%
Others 13.0%

 

W32/Noomy.a@MM is located on VIL at: http://vil.nai.com/vil/content/v_128744.htm

Security experts have warned internet users to update their antivirus systems to protect against a newly discovered worm dubbed Noomy.A, which "could represent a new trend in malicious code techniques".

 

W32/Lovgate-V is a variant of the W32/Lovgate family of worms that spread via email, network shares and filesharing networks.

W32/Lovgate-V copies itself to the Windows system folder as the files WinHelp.exe, iexplore.exe, kernel66.dll and ravmond.exe and to the Windows folder as systra.exe.

The worm also drops the files msjdbc11.dll, mssign30.dll and odbc16.dll which
provide unauthorized remote access to the computer over a network.

The worm drops ZIP files containing a copy of the worm onto accessible drives.
The ZIP file may also carry a RAR extension. The name of the packed file is chosen from the following list:

WORK
setup
important
bak
letter
pass

The name of the contained unpacked file is either PassWord, email or book, with a file extension of EXE, SCR, PIF or COM.

In addition W32/Lovgate-V copies itself to the file command.exe in the root folder and creates the file autorun.inf there containing an entry to run the dropped file upon system startup.

W32/Lovgate-V spreads by email. Email addresses are harvested from WAB, TXT,
HTM, SHT, PHP, ASP, DBX, TBB, ADB and PL files found on the system.

Emails have the following characteristics:

Subject line:

test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message text:

It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.

The message contains Unicode characters and has been sent as a binary attachment.

Mail failed. For further assistance, please contact!

Attached file:

document
readme
doc
text
file
data
test
message
body

followed by ZIP, EXE, PIF or SCR.

W32/Lovgate-V also enables sharing of the Windows media folder and copies itself there using various filenames.

The worm also attempts to reply to emails found in the user's inbox using the following filenames as attachments:

the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe

The worm attempts to spread by copying itself to mounted shares using one of the following filenames:

mmc.exe
xcopy.exe
winhlp32.exe
i386.exe
client.exe
findpass.exe
autoexec.bat
MSDN.ZIP.pif
Cain.pif
WindowsUpdate.pif
Support Tools.exe
Windows Media Player.zip.exe
Microsoft Office.exe
Documents and Settings.txt.exe
Internet Explorer.bat
WinRAR.exe

W32/Lovgate-V also attempts to spread via weakly protected remote shares by connecting using a password from an internal dictionary and copying itself as the file NetManager.exe to the system folder on the admin$ share.

After successfully copying the file W32/Lovgate-V attempts to start it as the service "Windows Managment Network Service Extensions" on the remote computer.

W32/Lovgate-V starts a logging thread that listens on port 6000, sends a notification email to an external address and logs received data to the file C:\Netlog.txt.

W32/Lovgate-V attempts to terminate processes containing the following strings:

rising
SkyNet
Symantec
McAfee
Gate
Rfw.exe
RavMon.exe
kill
Nav
Duba
KAV
KV

W32/Lovgate-V also overwrites EXE files on the system with copies of itself. The original files are saved with a ZMX extension.
 

This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

Copyright © 1998 The Computer Guys

 Back Home Up Next