PDA

View Full Version : lovgate worm - advise requested


kumarc
06-05-2005, 07:57 AM
I recently received two emails (pasted below) stating that email sent from my domain included the lovgate worm and I am not sure how to respond.

I read through the forum about the Sobig.F virus that seems to have similar characteristics and, if I understand correctly, there is nothing to be done except to ensure that my local computer is virus-free… Should I assume that this is a similar situation?

Other information that may or may not be relevant:
- None of my email accounts forward to an external address nor have auto-responders
- Scanning my local computer with security software shows it to be clean of viruses.
- Neither email is shown in my sent folder of Outlook.
- The address from which the first was sent is a legitimate account, but one that I do not use except as a forwarding alias to another internal email account
- The address from which the second was sent is not a registered account on my domain
- FutureQuest’s built-in virus filter is, of course, enabled

Any advice on how to respond is greatly appreciated.

Thanks,

Kumar




Message 1
------------------------------------------------------------
Your message (header below) has been deleted because of the following error:
A virus of type Virus identified I-Worm/Lovgate.T was detected in attachment data.zip

------ Original Message Header ------
Received: from xpat.us[66.110.19.94] by webserver.nss.local;
Mon, 30 May 2005 12:10:25 +0100
From: ak@xpat.us
To: julie@writersbureau.com
Subject: hi
Date: Mon, 30 May 2005 14:10:26 +0300
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0013_544665DF.3330D346"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <f050530121022BA69@local>
------------------------------------------------------------

Message 2
------------------------------------------------------------
The attachment(s) that you sent with the following mail
had Viruses in it!

=============================================================
The Mail came from : linda@xpat.us
The Mail recipient : brian@ucc.co.tz
Subject of the Mail : Hi
Message-ID :

Attachment-Name Virus-Name Action-Taken
------------------------------------------------------------
message.zlo Email-Worm.Win32.LovGate.w Deleted
=============================================================

Bob
06-05-2005, 08:55 AM
Hello Kumar,

You would want to investigate the raw headers of the emails, if available, to ensure that they did not originate from your account, which most likely they did not:
http://Service.FutureQuest.net/index.php?_a=knowledgebase&_j=questiondetails&_i=107

It is very common for both spammers and virus writers to send email showing a forged From: address and in some instances they send an email to an address and then list the same address as the From: address as well.

Assuming that they are not from your account and your machine is virus free then your best bet is to look at implementing a filter to delete these types of emails before they ever reach you.
http://Service.FutureQuest.net/index.php?_a=knowledgebase&_j=subcat&_i=33

-Bob

kumarc
06-05-2005, 09:29 AM
Hello Bob,

As you suspected, the email did not originate from my account.

I read through the Knowledgebase that you linked me to and will implement the advised measures.

Thanks,

Kumar