PDA

Click to See Complete Forum and Search --> : Heads Up**W32.HLLW.Lovgate.L@mm


Und3ertak3r
June 26th, 2003, 10:41 AM
Hi Guys,

This has been a busy day for virii ..

Here is the latest.. version of Lovgate, info from Symantec (http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.l@mm.html)
No information for this version on McAfee at this time.
Listed as Version G with RAV (http://www.ravantivirus.com/virus/showvirus.php?v=182)
Appears to be version M on Sophos (http://www.sophos.com/virusinfo/analyses/w32lovgatem.html)


Distribution: High
Damage: Medium
Wild: Low


The W32.HLLW.Lovgate.L@mm worm is a variant of W32.HLLW.Lovgate.I@mm. This worm has been repacked to make it difficult for antivirus software to detect it.

For more information about the worm, refer to the W32.HLLW.Lovgate.I@mm writeup.



Also Known As: I-Worm.Lovgate.i [KAV]
Type: Worm
Infection Length: 163,587 bytes
Systems Affected: Windows NT, Windows 2000, Windows XP
Systems Not Affected: Windows 3.x, Macintosh, OS/2, UNIX, Linux

Cemetric
June 26th, 2003, 10:25 PM
If you are running Mcafee you might wanna update your engine (if you didn't allready)

Read all about why here : Update Mcafee engine to 4.2.60 (http://www.nai.com/us/downloads/updates/engine.asp)

I've encountered a problem with the previous engine ... if a server or pc got infected with the Lovgate and the klez virus together .. A key in the registry (wich starts the shield at startup)
would disapear and the virusses would have their way ...
One of our servers got as much as 16000 of those pesty lovgates at 158kb a piece ... you do the math.

Any way :D was a bit frustrated with this virus it can do a lot of damage if your company doesn't know much about antivirus...and you have to do everything manualy (300 servers updating by hand because they don't see the advantage of an enterprise edition :rolleyes: )

And then I didn't mntion the 6000 client pc's (yes 6000) ...no way am I gonna do those manualy :eek:

Und3ertak3r
June 27th, 2003, 10:28 AM
And the fun part of lovgate.. It is network aware.. ie it looks for file shares to spread/update itself.. Cool..huh

Thanks Cemetric for that warning regarding McAfee

Cheers

Cemetric
June 27th, 2003, 11:40 PM
And the fun part of lovgate.. It is network aware.. ie it looks for file shares to spread/update itself.. Cool..huh

Thnx Und3ertak3r forgot to mention that ...it does indeed use shares to distribute itself ...

Thanks Cemetric for that warning regarding McAfee

No worries ..I'm here to please ;)

Greetz

GenericAssassin
June 27th, 2003, 11:46 PM
Thanks alot for the heads up. Keep us posted on any developments.