Net-Worm:W32/Lovsan.E

Classification

Malware

Net-Worm

W32

Lovsan.E

Summary

The new E variant of Net-Worm:W32/Lovsan was found on August 29th, 2003.

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Manual Disinfection

CAUTION Manual disinfection is a risky process; it is recommended only for advanced users.

For full 8-step list of how to get rid of Lovsan, please see Net-Worm:W32/Lovsan

Network Disinfection

For general instructions on disinfecting a local network infection, please see Eliminating A Local Network Outbreak.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

This variant is functionally identical to Lovsan.A with a few minor differences:

  • It uses the file name mslaugh.exe instead of MSBLAST.EXE.
  • It uses a different MUTEX name: 'SILLY'
  • The Distributed Denial of Service (DDoS) target has been changed to kimble.org, which already points to 127.0.0.1, effectively causing the infected hosts to attack themselves
  • The used registry value has been changed to: 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Automation'
  • It has a different hidden message: 'I dedicate this particular strain to me ANG3L - hope yer enj oying yerself and dont forget the promise for me B/DAY !!!!'

Date Created: -

Date Last Modified: -