Content
W32/Lovgate.q@M
- Type
- Virus
- SubType
- Worm
- Discovery Date
- 03/22/2004
- Length
- 114,176 bytes
- Minimum DAT
- 4340 (03/22/2004)
- Updated DAT
- 4907 (11/29/2006)
- Minimum Engine
- 5.1.00
- Description Added
- 03/24/2004
- Description Modified
- 10/05/2004 7:46 PM (PT)
Tab Navigation
Characteristics
This detection is for a new variant of W32/Lovgate. It bears the following characteristics:
- Mails itself, constructing message uses its own SMTP engine. Email attachment may be a ZIP archive. Mails are sent in reply to email messages found on the victim machine.
- Drops a backdoor component (detected as BackDoor-AQJ with 4339 DATS and above)
- Attempts to copy itself to poorly secured remote shares, scanning contiguous IP ranges, seeking accessible IPC$ or ADMIN$ shares.
Such copies of the worm may be enticingly named, or within ZIP or RAR archives. The worm carries a list of typical username/password combinations which it uses in attempting to get write access to remote shares - If it is able to access a remote share, it copies itself there as NETMANAGER.EXE, and remotely executes itself as a service on the remote machine.
- Creates a share on the victim machine (share name "MEDIA").
- Renames the extensions of EXE files to ZMX.
- Terminates certain processes
Proactive Detection
This worm is detected as virus or variant W32/Sluter.worm.gen
with the 4298 DATs or greater, with scanning of compressed files enabled. Precise detection as W32/Lovgate.q@MM will be provided by the DATs specified above.
The backdoor component dropped by this worm is detected as BackDoor-AQJ with the 4339 DATs or greater.
Symptoms
When the worm is executed, various files are dropped on the system. The following are copies of the worm (114, 176 bytes):
- %SysDir%\IEXPLORE.EXE
- %SysDir%\kernel66.dll
- %SysDir%\RAVMOND.exe
- %WinDir%\SYSTRA.EXE
- C:\COMMAND.EXE
An AUTORUN.INF file is also dropped to C:\, intended to run COMMAND.EXE via Windows auto-run feature.
The following DLLs are also dropped (all identical). This is the remote access component, (detected as BackDoor-AQJ):
- %SysDir%\msjdbc11.dll
- %SysDir%\MSSIGN30.DLL
- %SysDir%\ODBC16.dll
A copy of the worm in a RAR or ZIP archive may also be added to the root of C:\, for example:
- bak.RAR
- Important.RAR
- pass.RAR
- setup.RAR
- WORK.RAR
- setup.ZIP
- letter.ZIP
The following Registry keys are added in order to run the worm at system startup:
- HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
"run" = RAVMOND.exe - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Program In Windows" = %SysDir%\IEXPLORE.EXE - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
runServices "SystemTra" = %WinDir%\SysTra.EXE
The following key is added to run the backdoor component at system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "VFW Encoder/Decoder Settings" =
RUNDLL32.EXE MSSIGN30.DLL ondll_reg
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "Protected Storage" = RUNDLL32.EXE mssign30.dll ondll_reg
The backdoor component is also installed as services on the victim machine, bearing the following characteristics:
Service 1
Display name:
_reg
ImagePath:
Rundll32.exe msjdbc11.dll ondll_server
Startup:
automatic
Service 2
Display name:
Windows Management Protocol v.0 (experimental)
Description:
Windows Advanced Server. Performs scheduled scans for LANguard.
ImagePath:
Rundll32.exe msjdbc11.dll ondll_server
Startup:
automatic
The following Registry keys house the services information:
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_reg
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows
Management Protocol v.0 (experimental)
If the worm is able to copy itself to remote shares, it attempts to execute itself remotely. It does this by copying itself as:
- ADMIN$\SYSTEM32\LLSSRVER.EXE
and remotely executing it as a service. The service bears the following characteristics:
Display name:
Windows Management Service
ImagePath:
llssrver.exe -exe_start
Startup:
Automatic
The worm attempts to gain access to the IPC$ share on remote systems by using a dictionary style attack, similarily to the W32/Lovgate.f@M variant.
If successful, the worm copies itself to all accessible shares, using the filenameslisted below:
- Thank you.doc.exe
- 3D Flash Animator.rar.bat
- SWF Browser2.93.txt.exe
- Download.exe
- Panda Crack.zip.exe
- WinRAR V3.2.0 Beta 2.exe
- Swish2.00.pif
- AAdobe Photoshop7.0 creak.pif
- You_Life.JPG.pif
- CloneCD crack.exe
- WinZip v9.0 Beta Build 5480 crack.exe
- Real-DRAW PRO v3.10.exe
- Star Wars Downloader.exe
- HyperSnap-DX v5.20.01.exe
- Adobe Photoshop6.0.zip.exe
- HyperSnap-DX v4.51.01.exe
Email propagation
The worm replies to unread messages in Microsoft Outlook and Outlook Express inboxes and deletes the messages after responding to them.
Subject:
Re: Original subject
Body:
======
original message body
======
YAHOO.COM Mail
auto-reply:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE YAHOO.COM Mail now! <
Attachment: (one of the following)
- the hardcore game-.pif
- Sex in Office.rm.scr
- Deutsch BloodPatch!.exe
- s3msong.MP3.pif
- Me_nude.AVI.pif
- How to Crack all gamez.exe
- Macromedia Flash.scr
- SETUP.EXE
- Shakira.zip.exe
- dreamweaver MX (crack).exe
- StarWars2 - CloneAttack.rm.scr
- Industry Giant II.exe
- DSL Modem Uncapper.rar.exe
- joke.pif
- Britney spears nude.exe.txt.exe
- I am For u.doc.exe
As for contstructing mesages using it's own SMTP engine:
Subject can be any of the following:
- hi
- hello
- Hello
- Mail transaction Failed
- mail delivery system
Body of the message could be any of the following:
- Mail failed. For further assistance, please contact!
- The message contains Unicode characters and has been sent as a binary attachment.
- It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Attachment: (could be randomly constructed string with the following extensions):
- EXE
- PIF
- SCR
- ZIP
- TMP
- HTM
Termination of Processes
It also searches running processes for the following list of strings, and kills those it finds:
- rising
- SkyNet
- Symantec
- McAfee
- Gate
- Rfw.exe
- RavMon.exe
- kill
- NAV
- Duba
- KAV
- KV
The worm looks for EXE files on the system and renames their extensions to *.ZMX. It then copies itself using the original EXE filename.
e.g., Explorer.exe becomes Explorer.zmx. Then the worm will copy itself as Explorere.exe so everytime Windows Explorer is invoked the worm will run instead.
Method of Infection
- This worm spreads via Email.
- In attempting to copy itself to poorly secured network shares (IPC$ and ADMIN$), the worm generates a significant amount of network traffic. It scans contiguous IP ranges (on port 445) looking for accessibly shares (brute forces with the usernames/passwords it carries).
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
This detection is for a new variant of W32/Lovgate. It bears the following characteristics:
- Mails itself, constructing message uses its own SMTP engine. Email attachment may be a ZIP archive. Mails are sent in reply to email messages found on the victim machine.
- Drops a backdoor component (detected as BackDoor-AQJ with 4339 DATS and above)
- Attempts to copy itself to poorly secured remote shares, scanning contiguous IP ranges, seeking accessible IPC$ or ADMIN$ shares.
Such copies of the worm may be enticingly named, or within ZIP or RAR archives. The worm carries a list of typical username/password combinations which it uses in attempting to get write access to remote shares - If it is able to access a remote share, it copies itself there as NETMANAGER.EXE, and remotely executes itself as a service on the remote machine.
- Creates a share on the victim machine (share name "MEDIA").
- Renames the extensions of EXE files to ZMX.
- Terminates certain processes
Proactive Detection
This worm is detected as virus or variant W32/Sluter.worm.gen
with the 4298 DATs or greater, with scanning of compressed files enabled. Precise detection as W32/Lovgate.q@MM will be provided by the DATs specified above.
The backdoor component dropped by this worm is detected as BackDoor-AQJ with the 4339 DATs or greater.
Symptoms
Symptoms -
When the worm is executed, various files are dropped on the system. The following are copies of the worm (114, 176 bytes):
- %SysDir%\IEXPLORE.EXE
- %SysDir%\kernel66.dll
- %SysDir%\RAVMOND.exe
- %WinDir%\SYSTRA.EXE
- C:\COMMAND.EXE
An AUTORUN.INF file is also dropped to C:\, intended to run COMMAND.EXE via Windows auto-run feature.
The following DLLs are also dropped (all identical). This is the remote access component, (detected as BackDoor-AQJ):
- %SysDir%\msjdbc11.dll
- %SysDir%\MSSIGN30.DLL
- %SysDir%\ODBC16.dll
A copy of the worm in a RAR or ZIP archive may also be added to the root of C:\, for example:
- bak.RAR
- Important.RAR
- pass.RAR
- setup.RAR
- WORK.RAR
- setup.ZIP
- letter.ZIP
The following Registry keys are added in order to run the worm at system startup:
- HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
"run" = RAVMOND.exe - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Program In Windows" = %SysDir%\IEXPLORE.EXE - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
runServices "SystemTra" = %WinDir%\SysTra.EXE
The following key is added to run the backdoor component at system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "VFW Encoder/Decoder Settings" =
RUNDLL32.EXE MSSIGN30.DLL ondll_reg
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "Protected Storage" = RUNDLL32.EXE mssign30.dll ondll_reg
The backdoor component is also installed as services on the victim machine, bearing the following characteristics:
Service 1
Display name:
_reg
ImagePath:
Rundll32.exe msjdbc11.dll ondll_server
Startup:
automatic
Service 2
Display name:
Windows Management Protocol v.0 (experimental)
Description:
Windows Advanced Server. Performs scheduled scans for LANguard.
ImagePath:
Rundll32.exe msjdbc11.dll ondll_server
Startup:
automatic
The following Registry keys house the services information:
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_reg
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows
Management Protocol v.0 (experimental)
If the worm is able to copy itself to remote shares, it attempts to execute itself remotely. It does this by copying itself as:
- ADMIN$\SYSTEM32\LLSSRVER.EXE
and remotely executing it as a service. The service bears the following characteristics:
Display name:
Windows Management Service
ImagePath:
llssrver.exe -exe_start
Startup:
Automatic
The worm attempts to gain access to the IPC$ share on remote systems by using a dictionary style attack, similarily to the W32/Lovgate.f@M variant.
If successful, the worm copies itself to all accessible shares, using the filenameslisted below:
- Thank you.doc.exe
- 3D Flash Animator.rar.bat
- SWF Browser2.93.txt.exe
- Download.exe
- Panda Crack.zip.exe
- WinRAR V3.2.0 Beta 2.exe
- Swish2.00.pif
- AAdobe Photoshop7.0 creak.pif
- You_Life.JPG.pif
- CloneCD crack.exe
- WinZip v9.0 Beta Build 5480 crack.exe
- Real-DRAW PRO v3.10.exe
- Star Wars Downloader.exe
- HyperSnap-DX v5.20.01.exe
- Adobe Photoshop6.0.zip.exe
- HyperSnap-DX v4.51.01.exe
Email propagation
The worm replies to unread messages in Microsoft Outlook and Outlook Express inboxes and deletes the messages after responding to them.
Subject:
Re: Original subject
Body:
======
original message body
======
YAHOO.COM Mail
auto-reply:
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
> Get your FREE YAHOO.COM Mail now! <
Attachment: (one of the following)
- the hardcore game-.pif
- Sex in Office.rm.scr
- Deutsch BloodPatch!.exe
- s3msong.MP3.pif
- Me_nude.AVI.pif
- How to Crack all gamez.exe
- Macromedia Flash.scr
- SETUP.EXE
- Shakira.zip.exe
- dreamweaver MX (crack).exe
- StarWars2 - CloneAttack.rm.scr
- Industry Giant II.exe
- DSL Modem Uncapper.rar.exe
- joke.pif
- Britney spears nude.exe.txt.exe
- I am For u.doc.exe
As for contstructing mesages using it's own SMTP engine:
Subject can be any of the following:
- hi
- hello
- Hello
- Mail transaction Failed
- mail delivery system
Body of the message could be any of the following:
- Mail failed. For further assistance, please contact!
- The message contains Unicode characters and has been sent as a binary attachment.
- It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Attachment: (could be randomly constructed string with the following extensions):
- EXE
- PIF
- SCR
- ZIP
- TMP
- HTM
Termination of Processes
It also searches running processes for the following list of strings, and kills those it finds:
- rising
- SkyNet
- Symantec
- McAfee
- Gate
- Rfw.exe
- RavMon.exe
- kill
- NAV
- Duba
- KAV
- KV
The worm looks for EXE files on the system and renames their extensions to *.ZMX. It then copies itself using the original EXE filename.
e.g., Explorer.exe becomes Explorer.zmx. Then the worm will copy itself as Explorere.exe so everytime Windows Explorer is invoked the worm will run instead.
Method of Infection
Method of Infection -
- This worm spreads via Email.
- In attempting to copy itself to poorly secured network shares (IPC$ and ADMIN$), the worm generates a significant amount of network traffic. It scans contiguous IP ranges (on port 445) looking for accessibly shares (brute forces with the usernames/passwords it carries).
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A