Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32/Lovgate-W

Mar 24, 2004 12:25AM PST

Aliases
W32/Sluter.worm.gen, W32.Lovgate.Gen@mm, Win32/Lovgate.W

Type
Win32 worm

Description
W32/Lovgate-W is a worm with backdoor functionality that spreads via email, network shares with weak passwords and filesharing networks.
W32/Lovgate-W may arrive in an email with varying characteristics.

When executed W32/Lovgate-W creates a background process with the name LSASS.EXE, copies itself to the Windows system folder, sets registry entries, extracts a backdoor component as a DLL file, harvests email addresses from *.HT files and sends itself out.


More: http://www.sophos.com/virusinfo/analyses/w32lovgatew.html

Discussion is locked