|
|
|
Now Position: Home>Tech
Articles>Free Invasion from
Worms |
|
|
|
How to Detect and Remove Lovgate.AD Worm? |
|
What
is the Lovgate.AD worm?
Lovgate.AD, the new variant of W32/Lovgate is
packed multiple times.
Again, the backdoor component this variant
drops is already detected as BackDoor-AQJ
since the 4339 DATs.
Like its predecessors, this worm bears the
following characteristics:
- drops a backdoor component
- attempts to copy itself to accessible or
poorly secured remote shares, scanning
contiguous IP ranges, seeking accessible IPC$
or ADMIN$ shares.
- creates a share on the victim machine (share
name "MEDIA").
- mails itself, constructing message uses its
own SMTP engine. Email attachment may be a ZIP
archive. Additionally, mails may be sent in
reply to email messages found on the victim
machine (MAPI).
- performs companion virus infection of EXE
files (replacing original file with a copy of
itself, and renaming original with a .ZMX
extension).
- terminates processes associated with various
AV and security products
Also known as: I-Worm.Lovgate.ae,
W32.Lovgate.Y@mm
How to Remove the Lovgate.AD worm?
Using powerful McAfee
VirusScan 2004 to remove Lovgate.AD and
any other viruses.
-
If you are running Windows Me or Windows XP, we
recommend that you temporarily turn off System
Restore before virus scan.
For instructions on how to turn off System
Restore, read your Windows documentation, or one
of the following articles: How
to Disable System Restore in Windows ME or
Windows XP.
-
Before continuing, we strongly recommends that
you back up the registry before making any
changes to it.
- Click Start > Run.
- Type regedit
Then click OK.
- Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- In the right pane, delete the values:
- "Winhelp" =
"%system%\TkBellExe.exe..."
- "Hardware Profile" =
"%system%\hxdef.exe..."
- "Program in
Windows"="%system%\IEXPLORE.exe"
- "Microsoft NetMeeting
Associates, Inc." = "NetMeeting.exe"
- "Protected
Storage"="RUNDLL32.exe
MSSIGN30.DLL ondll_reg..."
- "VFW Encoder/Decoder
Settings"="RUNDLL32.exe
MSSIGN30.DLL ondll_reg"
- "WinHelp"="%system%\WinHelp.exe"
- "Shell Extension" =
"%system%\spollsv.exe"
- Do one of the following:
- If you are using Windows NT/2000/XP,
skip to step h.
- If you are using Windows 95/98/Me,
proceed with step f.
- Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices
- In the right pane, delete the values:
"SystemTra"="%Windir%\SysTra.exe"
"COM++ System" = "svchost.exe..."
When you have deleted these values,
proceed with step j.
- Navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows
NT\CurrentVersion\Windows
- In the right pane, delete the value:
"run"="RAVMOND.exe"
- Navigate to the key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
- In the left hand pane, delete the
subkeys:
_reg
Windows Management Protocol
v.0(experimental
- Exit the Registry Editor.
- Do one of the following:
- If you are using Windows NT/2000/XP,
skip to section 6, "To scan for
and delete the infected files."
- If you are using Windows 95/98/Me,
proceed with section 5.
-
If you are running Windows 95/98/Me, follow these
steps:
- The function you perform depends on your
operating system:
- Windows 95/98: Go to step B.
- Windows Me: If you are running
Windows Me, the Windows Me file-protection
process may have made a backup copy of the
Win.ini file that you need to edit. If
this backup copy exists, it will be in the
C:\Windows\Recent folder. Symantec
recommends that you delete this file
before continuing with the steps in this
section. To do this:
- Start Windows Explorer.
- Browse to and select the
C:\Windows\Recent folder.
- In the right pane, select the Win.ini
file and delete it. The Win.ini
file will be regenerated when you save
your changes to it in step F.
- Click Start > Run.
- Type the following:
edit c:\windows\win.ini
and then click OK.
(The MS-DOS Editor opens.)
Note: If Windows is installed in a
different location, make the appropriate path
substitution.
- In the [windows] section of the
file, look for a line similar to:
run=ravmond.exe
- If this line exists, delete everything to
the right of run=
- Click File > Save.
- Click File > Exit.
4. Scan for and delete the infected files using powerful McAfee
VirusScan 2004.
5. As Lovgate.AD
renames many .exe files, rename them to the
correct extension for them to work.
- Follow the instructions for your operating
system:
- Windows 98/Me/2000
- On the Windows desktop, click the Start
button > Find or Search > Files or
Folders.
- In the Search Results window, set
"Look in" to the first
removable, mapped, or fixed drive type
with a drive letter greater than E.
- Check Include subfolders.
- In the "Named" or
"Search for..." box, type,
or copy and paste, the following:
*.zmx
- Click Find Now or Search
Now.
- Windows XP
- On the Windows desktop, click the Start
button > Search.
- Click All files and folders.
- In the All or part of the file
name box, type, or copy and paste,
the following:
*.zmx
- Verify that "Look in" is
set to the first removable, mapped, or
fixed drive type with a drive letter
greater than E.
- Click More advanced options.
- Select Search system folders.
- Select Search subfolders.
- Select Search hidden files and
folders.
- Click Search.
- For every file that is found, right click
it, select Rename, and then change the
.zmx extension to .exe.
- Repeat step 6 for every removable, mapped,
or fixed drive type with a drive letter
greater than E.
How to Disinfect My Computer from Worms?
In order to keep your computer protected, bear
the following tips in mind:
- If you have filtering tools installed,
configure them to reject messages with the
characteristics described above. If, in spite
of doing this, you receive the message that
contains the virus: do not open it, do not run
the attached file and delete it, making sure
that you also delete it from the Deleted
Items folder.
- Install a good antivirus in your computer.
Select McAfee
VirusScan 2004 to get the Kaspersky antivirus solution that best suits your needs.
- Keep your antivirus updated. If automatic
updates are available, configure your
antivirus to use them.
- Keep your permanent antivirus protection
enabled at all times.
Detect and Removal Instruction for Other
Worms - 'L':
| |
|
|
|
 |
|
|
|
|
 |
PQ DVD to iPod Video Suite
PQ DVD to iPod Video Suite (PQ DVD to iPod + iPod Video Converter) is a One-Click, All-In-One solution to convert DVD, Tivo, DivX, MPEG, WMV, AVI, RealMedia and many more to iPod Video ... |
 |
Kaspersky Internet Security
Internet Security processes all incoming and outgoing data on your computer, including email, Internet traffic and network interaction, without the need for additional security applications ... |
| Cucusoft MPEG/AVI to DVD/VCD/SVCD Converter Pro
It enables you to convert and burn any video file directly to VCD, DVD, SVCD, MPEG1 and MPEG2 format. Pro version included all the features of the lite version ... |
 |
SpyNoMore
SpyNoMore scans, cleans and blocks spyware as well as any other good anti-spyware product, but with one big advantage, Custom Fix (patent pending). Spyware programs are growing more sophisticated by the day ... |
|
|
|
|
|
|
|
|