Search:       

Monday, 12 May 2008       

I-Worm.Lovelorn. Spyware/Adware Definition


Name: I-Worm.Lovelorn.
Category: Viruses
Description: Details
I-Worm.Lovelorn.a
Lovelorn spreads via the Internet as an email file attachment. The infected file is a Windows PE EXE file about 100KB in size and written in Borland C++.
Infected emails have the following possible characteristics:
Subject: Re:baby!your friend send this file to you !
Message text: Read this file

Subject: HELP??-
Message text: Helpall

Subject: Re:Get Password mail...
Message text: Enjoy

Subject: There're some Passwords here
Message text: Read File attach .

Subject: Re:Binladen_Sexy.jpg
Message text: run File Attach to extract:BinladenSexy.jpg...

Subject: The Sexy story and 4 sexy picture of BINLADEN !
Message text: Enjoy! BINLADEN:SEXY..

Subject: Re:I Love You...OKE!
Message text: Souvenir for you from file attach...

Subject: A Greeting-card for you .
Message text: See the Greeting-card .

Subject: Re:Kiss you..^@^
Message text: Read file attach

Subject: Guide to ...
Message text: I like Sexy with you.

Subject: Re:Baby! 2000USD,Win this game...
Message text: Play the game from file attach

Subject: Help
Message text: Help.

The name of the attached file is chosen arbitrarily and has the following extensions:
.Kiss.ok.exe
.HTM

The senders return address is falsified.
Installation
When launched the worm codes itself into the Windows system catalog under the following names:

Explorer.exe
Kernel32.exe
Netdll.dll
Serscg.dll

The Lovelorn worm then creates the files Setup.hrm, Bsbk.dll and Netsn.dll, all containing code in the MIME format. The worm then creates the file, 'Findfast.exe' in the Startup folder.
Next, the worm registers itself in the autorun key section of the system registry using the following entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
explorer=%System%explorer.exe

Propagation via Email
The Lovelone worm searches infected (victim) computers for the file extensions, '.dbx' and '.htm'. It then looks within files using these extensions for email addresses that it then records in the file 'Mssys.dll'. The addresses held in this file will be later used as recipients of virus copies. To send out infected email messages, Lovelorn uses a built-in SMTP server.
Infected files
The worm is able to infect PE application files, copying itself into the file headers.
Propagation via diskette
Lovelorn copies itself on the A: drive under the name 'NQH_Kiss_you.exe'.


Top Viruses Visited Pages:
DieHard2.4000.
DoS.Win32.DieWa
ECW.57
Geek.45
Gorgan.271
Gorill
Guerilla.199
HLLP.Nover.771
Holiday Famil
Horror.111
HS.90
Hydra_II Famil
I-Worm.Lovelorn.
I-Worm.Mimail.
I-Worm.MyLife.

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us



Partners
Softs Land
Hotel Reservations
Computer Articles
Viruses Info
Free Downloads
Data Recovery Shareware Downloads Free Articles
Cooks Recipes
Download Programs
Windows Drivers
MySpace Generators

Check PageRank

 

 

- Privacy Policy -