Content
W32/Lovsan.worm.c
- Type
- Virus
- SubType
- Internet Worm
- Discovery Date
- 08/13/2003
- Length
- 7,200 bytes
- Minimum DAT
- 4285 (08/13/2003)
- Updated DAT
- 4323 (02/11/2004)
- Minimum Engine
- 5.1.00
- Description Added
- 08/13/2003
- Description Modified
- 08/13/2003 1:45 PM (PT)
Risk Assessment
- Corporate User
- Low-Profiled
- Home User
- Low-Profiled
Tab Navigation
Characteristics
This threat was proactively detected as a variant of the Exploit-DcomRpc virus with the 4283 DAT files when scanning compressed executables. The 4285 DAT files will identify this virus as Exploit-DcomRpc (non-variant) when scanning compressed executables (default setting).
This is a variant of W32/Lovsan.worm. It is functionally the same as the original variant with the exception of the filename.
- File name
- penis32.exe
Symptoms
Presence of the following files in %WinDir%\System32 directory:
- penis32.exe (7,200 bytes) (worm)
Method of Infection
See W32/Lovsan.worm.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- W32.Blaster.B.Worm (Symantec)
- W32/Blaster.worm.c
Characteristics
Characteristics -
This threat was proactively detected as a variant of the Exploit-DcomRpc virus with the 4283 DAT files when scanning compressed executables. The 4285 DAT files will identify this virus as Exploit-DcomRpc (non-variant) when scanning compressed executables (default setting).
This is a variant of W32/Lovsan.worm. It is functionally the same as the original variant with the exception of the filename.
- File name
- penis32.exe
Symptoms
Symptoms -
Presence of the following files in %WinDir%\System32 directory:
- penis32.exe (7,200 bytes) (worm)
Method of Infection
Method of Infection -
See W32/Lovsan.worm.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A