Home / malwarePDF  

Net-Worm:W32/Lovsan.H


First posted on 15 June 2010.
Source: SecurityHome

Aliases :

There are no other names known for Net-Worm:W32/Lovsan.H.

Explanation :

A type of worm that replicates by sending complete, independent copies of itself over a network.

Additional DetailsThe new H variant of Net-Worm:W32/Lovsan was found on February 3rd, 2004.

This is a minor variant of Lovsan.A. Instead of MSBLAST.EXE, Lovsan.H uses file name MSCHOST.EXE.

The registry value it adds have been changed to
€ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shellext.32
The text inside the body has been patched to

Can you hear me? I LOVE YOU SAN!!.
Sucky gates why do you made this windows?
Stop fooling around and make good things!!!


Detection


F-Secure Anti-Virus detects Lovsan.H with the current database updates. This variant is detected by F-Secure Anti-Virus as: Worm.Win32.Lovesan.a

Last update 15 June 2010

 

TOP