Home > Threat descriptions >

Net-Worm:W32/Lovsan.B

Classification

Category: Malware

Type: Net-Worm

Aliases: Net-Worm:W32/Lovsan.B

Summary


The new B variant of Net-Worm:W32/Lovsan was found on August 13th 2003.

Removal


Automatic action

Once detected, the F-Secure security product will automatically handle a harmful program or file by either deleting or renaming it.

Eliminating a Local Network Outbreak

If the infection is in a local network, please follow the instructions on this webpage:

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details


A dropper available on a web page drops two files in Windows System folder and adds them to the Windows registry:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

The first file called Root32.exe is a backdoor and the second one called teekids.exe is the actual worm.

This new variant is functional identical to the previous Lovsan, only the text and the file name have been changed.