
 |
|
|
|
|
F-Secure Virus Descriptions : Lovsan.H
A new variant of Lovsan(Blaster) worm, Lovsan.H was found on
February 3rd, 2004.
This is a minor variant of Lovsan.A. Instead of MSBLAST.EXE,
Lovsan.H uses file name MSCHOST.EXE.
The registry value it adds have been changed to
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shellext.32
The text inside the body has been patched to
Can you hear me? I LOVE YOU SAN!!.
Sucky gates why do you made this windows?
Stop fooling around and make good things!!!
Detection
F-Secure Anti-Virus detects Lovsan.H with the current database updates.
This variant is detected by F-Secure Anti-Virus as:
Worm.Win32.Lovesan.a
Description:
Katrin Tocheva and Gergely Erdelyi; February 3rd, 2004;
F-Secure Corporation
|
|
|
|
|
|