Worm.Win32.Perlovga

Detect Date 04/29/2008
Class Worm
Platform Win32
Description

The worm copies files from its working folders:

%WorkDir%host.exe



%WorkDir%autorun.inf

to the Windows root directory:

%WinDir%svchost.exe



%WinDir%autorun.inf

It then launches the following file for execution:

%WinDir%svchost.exe

and ceases running.