New Lovgate worm versions - complex and highly destructive
This article warns regarding the increased complexity and destructivity of the most recent variants of the Lovgate worm.
http://zdnet.com.com/2100%2D1105_2%2D5260304.html
The latest variant of the Lovgate worm scans PCs for executable files and then renames them, a tactic used by viruses from a much older generation, according to antivirus companies. The Lovgate worm first appeared in February 2003 and has since mutated many times. The most recent versions of the worm--Lovgate.AE and Lovgate.AH--were discovered on Sunday.
They spread by e-mailing themselves to addresses found on an infected machine and then open a "back door" to give control of the infected system to an attacker. Finally, the worms scan for vulnerable PCs connected to the infected system's local network--using the same Windows vulnerability exploited by the MSBlast worm almost a year ago.
The most important difference is the worm's destructive nature. Although the latest Lovgate worm does not delete any user data--such as documents or spreadsheets--it replaces executable files (with the .exe extension) on the local hard drive with further copies of itself. This process can leave an infected computer effectively useless because it is unable to run any applications.
MOST RECENT LOVGATE EXAMPLES:
http://www.symantec.com/avcenter/venc/data/w32.lovgate.ab@mm.html
http://www.symantec.com/avcenter/venc/data/w32.lovgate.y@mm.html
http://vil.nai.com/vil/content/v_126669.htm
LOVGATE REMOVAL TOOL
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.removal.tool.html
The latest versions propagate through open network shares. It allows an attacker to access your computer. The email will have a variable subject and a file attachment with a .bat, .cmd, .exe, .pif, .scr, or .zip file extension. It spreads through the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
AVOID ALL ATTACHMENTS ENDING WITH: bat, cmd, exe, scr, pif, rar, zip