All the latest UK technology news, reviews and analysis

Lovgate worm thrives on a full inbox

by Iain Thomson

25 Feb 2003

Be the first to comment

  • Tweet this

A new variant of the Lovgate.C worm is on the loose and is punishing those of us who leave their inboxes stuffed with old email.

The worm doesn't take the usual route of mining your address book for email addresses to propagate itself.

Instead it replies to all the email addresses in your inbox as well as any incoming emails. It also checks for email addresses stored within web page caches that may be on your hard drive.

While it does not destroy data it does leave a Trojan that allows remote access to your computer via port 10168 and sends a message to either 54love@fescomail.net or hacker117@163.com.

Infected emails come with a variety of headers and one of the following attachments:

  • billgt.exe
  • card.exe
  • docs.exe
  • fun.exe
  • hamster.exe
  • humor.exe
  • images.exe
  • joke.exe
  • midsong.exe
  • news_doc.exe
  • pics.exe
  • PsPGame.exe
  • s3msong.exe
  • searchURL.exe
  • setup.exe
  • tamagotxi.exe

"It's a nice, if that's the right word, change as it takes it from the inbox rather than the address book," said Jack Clark, antivirus specialist at Network Associates.

"This makes it slower to spread but the recipients more likely to open it."

So far reports of actual infections are low. While it has been detected around the world it is nowhere near as common as Klez and Bugbear, which remain the two most common viruses despite the availability of removal utilities from all the major antivirus vendors.

"We've seen something of an increase in infections in the last day," said Graham Cluley, antivirus analyst at Sophos.

"It might creep into the top 10 but we've only had a handful of reports, although the website information page is registering a massive number of hits."

All major antivirus vendors now have patches available and users are urged to update their software to be secure.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

Senior Infrastructure Project Manager

Our highly successful client urgently requires Senior...

east midlands

Our client, a highly successful and currently market...

To send to more than one email address, simply separate each address with a comma.