Home > Threat descriptions >

Net-Worm:W32/Lovsan.E

Classification

Category: Malware

Type: Net-Worm

Aliases: Lovsan.E

Summary


The new E variant of Net-Worm:W32/Lovsan was found on August 29th, 2003.

Removal


Automatic action

Once detected, the F-Secure security product will automatically handle a harmful program or file by either deleting or renaming it.

Manual Disinfection

CAUTION Manual disinfection is a risky process; it is recommended only for advanced users.

For full 8-step list of how to get rid of Lovsan, please see Net-Worm:W32/Lovsan

Network Disinfection

For general instructions on disinfecting a local network infection, please see Eliminating A Local Network Outbreak.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details


This variant is functionally identical to Lovsan.A with a few minor differences:

  • It uses the file name mslaugh.exe instead of MSBLAST.EXE.
  • It uses a different MUTEX name: 'SILLY'
  • The Distributed Denial of Service (DDoS) target has been changed to kimble.org, which already points to 127.0.0.1, effectively causing the infected hosts to attack themselves
  • The used registry value has been changed to: 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Automation'
  • It has a different hidden message: 'I dedicate this particular strain to me ANG3L - hope yer enj oying yerself and dont forget the promise for me B/DAY !!!!'