http://vil.nai.com/vil/content/v_100559.htm


This detection is for another virus that exploits the MS03-026 vulnerability.

It is not related to the W32/Lovsan.worm.d variant described here.

Intentions of the worm:
This worm tries spreads by exploiting a hole in Microsoft Windows. It instructs a remote target system to download and execute the worm from the infected host. Once running, the worm terminates and deletes the W32/Lovsan.worm.a process and applies the Microsoft patch to prevent other threats from infecting the system through the same hole. When the system clock reaches Jan 1, 2004, the worm will delete itself upon execution.