Home / malware Net-Worm:W32/Lovsan.H
First posted on 15 June 2010.
Source: SecurityHomeAliases :
There are no other names known for Net-Worm:W32/Lovsan.H.
Explanation :
A type of worm that replicates by sending complete, independent copies of itself over a network.
Additional DetailsThe new H variant of Net-Worm:W32/Lovsan was found on February 3rd, 2004.
This is a minor variant of Lovsan.A. Instead of MSBLAST.EXE, Lovsan.H uses file name MSCHOST.EXE.
The registry value it adds have been changed to
€ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shellext.32
The text inside the body has been patched to
Can you hear me? I LOVE YOU SAN!!.
Sucky gates why do you made this windows?
Stop fooling around and make good things!!!
Detection
F-Secure Anti-Virus detects Lovsan.H with the current database updates. This variant is detected by F-Secure Anti-Virus as: Worm.Win32.Lovesan.a
Last update 15 June 2010