F - L O V S A N
---------------

The F-Lovsan utility disinfects computers infected with W32/Lovsan.A, W32/Lovsan.B,
W32/Lovsan.C worms and W32/Lovsan.E.

Disinfection procedure should be as follows:

1. Unpack the F-Lovsan utility from the provided ZIP archive either with WinZip
or PkUnzip utilities. A trial version of WinZip archiver can be downloaded from
the following website:

http://www.winzip.com/ddchomea.htm
                                   
2. Run the unpacked F-Lovsan.exe file from a hard disk to eliminate Lovsan worm
infection. You can run the utility by either doubleclicking on it from Windows
Explorer or you can start it from a command interpreter (COMMAND.COM or
CMD.EXE) by typing its name at command prompt and pressing 'Enter' (for
advanced users).

The tool performs to following steps to remove the Lovsan worm:

 - find and kill the running worm process

 - delete the worm from the hard disk

 - remove the following registry value
   (depending on the worm variant)

   HKLM\\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows auto update

   HKLM\\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Inet Xp..

   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Automation

IMPORTANT NOTES
---------------

Please note that you have to log in with Administrator privileges to be able to
remove the worm properly.

After disinfection the patch for the security vulnerabily used by worm must be
fixed by installing the patch from Microsoft:

http://www.microsoft.com/technet/security/bulletin/MS03-026.asp

If you have any problems using this utility please contact us on 
'anti-virus-support@f-secure.com' address.


