Threat Description

Net-Worm:​W32/Lovsan.E

Details

Aliases:Net-Worm:​W32/Lovsan.E, Net-Worm:​W32/Lovsan.E
Category:Malware
Type:Net-Worm
Platform:W32

Summary



A type of worm that replicates by sending complete, independent copies of itself over a network.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.

For more general information on disinfection, please see Removal Instructions .

Network Disinfection

For general instructions on disinfecting a local network infection, please see Eliminating A Local Network Outbreak.

Manual Disinfection

Caution: Manual disinfection is a risky process; it is recommended only for advanced users.

For full 8-step list of how to get rid of Lovsan, please see Net-Worm:W32/Lovsan



Technical Details



The new E variant of Net-Worm:W32/Lovsan was found on August 29th, 2003. This variant is functionally identical to Lovsan.A with a few minor differences:

  • It uses the file name mslaugh.exe instead of MSBLAST.EXE.
  • It uses a different MUTEX name: 'SILLY'
  • The Distributed Denial of Service (DDoS) target has been changed to kimble.org, which already points to 127.0.0.1, effectively causing the infected hosts to attack themselves
  • The used registry value has been changed to: 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Automation'
  • It has a different hidden message: 'I dedicate this particular strain to me ANG3L - hope yer enj oying yerself and dont forget the promise for me B/DAY !!!!'





SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More