You are here: silicon.com > Software > Security Strategy

Security Strategy

Virus alert: Two-faced Lirva threatening users

Email offers either security patch or pop music...

By CNET Networks

Published: 8 January 2003 12:20 GMT

Computer users are being warned about the presence of a new mass-mailing worm which arrives in a email offering either the latest Microsoft security patch or exclusive access to pop sensation Avril Lavigne's website.

Lirva (w32.Lirva@mm), also known as Naith, once active will attempt to email copies of itself to all contacts on an infected system, shut down all antivirus and firewall programs, and launch a web browser to open the Avril Lavigne website on an infected user's desktop. Periodically an infected machine will continue to log-on to the Avril Lavigne website.

Lirva uses the Iframe vulnerability, so on unpatched systems, the worm will automatically execute whether or not the attached file is opened.

Antivirus vendor MessageLabs reports that parts of the Lirva worm code very look familiar, so Lirva may turn out to be a variant of a known virus family.

The email which carries Lirva shows evidence of a growing trend towards social engineering in order to encourage users to open the email. In past years emails bearing viruses have increasingly purported to carry information, pictures or video clips of celebrities - normally attractive females - who are particularly popular at any one time. Previous viruses have piggy-backed upon the popularity of singer Jennifer Lopez, tennis ace Anna Kournikova and Latino popstar Shakira.

Subject lines to look out for when spotting emails which may potentially carry the Lirva virus are:

Fw: Prohibited customers...
Re: Brigade Ocho Free membership
Re: According to Daos Summit
Fw: Avril Lavigne - the best
Re: Reply on account for IIS-Security
Re: ACTR/ACCELS Transcriptions
Re: The real estate plunger
Fwd: Re: Admission procedure
Re: Reply on account for IFRAME-Security breach
Fwd: Re: Reply on account for Incorrect MIME-header

Robert Vamosi writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
3 rd line Wintel Support Engineer - Central London

Tivoli Enterprise Manager, Enterprise Security Manager, Tivoli Storage Manager, Symantec Anti-Virus and MSUS/BigFix etc. Data Backup, Replication and ...

Desktop Support Engineer- Contract- Galway

Antivirus admin Responding to call/emails from users Desktop Support Engineer- Contract- Galway A company based in Galway have a requirement for ...

SERVICE DESK OPERATIVE

Service Desk procedures, Active Directory, Exchange 2007, network and stand alone printers, USB devices, Anti Virus installations, updates and ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: