- Discovered:
- December 9, 2002
- Updated:
- February 13, 2007 11:52:30 AM
- Type:
- Virus
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.Lamin is a virus that infects Portable Executable (PE)* files. The virus also contains a keystroke logger and an IRC backdoor Trojan.
NOTE: Definitions that have dates earlier than December 9, 2002, may detect this threat as BloodHound.W32.1.
* What are Portable Executable (PE) files?
PE files are files that are portable across all Microsoft 32-bit operating systems. The same PE-format executable can be executed on any version of Windows 95, 98, Me, NT, 2000, and XP. All PE files are executable, but not all executable files are portable.
A common example of a Portable Executable file is a screen saver (.scr) file.
Backdoor
If the IRC Backdoor Trojan component was installed on the computer, it is possible that your system has been accessed remotely by an unauthorized user. For this reason it is impossible to guarantee the integrity of a system that has had such an infection. The remote user could have made changes to the system, including but not limited to the following:
- Stealing or changing passwords or password files
- Installing remote-connectivity host software, also known as backdoors
- Installing keystroke logging software
- Configuring firewall rules
- Stealing credit card numbers, banking information, personal data, and so on
- Deleting or modifying files
- Sending inappropriate or even incriminating material from a customer's email account
- Modifying access rights on user accounts or files
- Deleting information from log files to hide such activities
To be certain that your organization is secure, you must reinstall the operating system, restore files from a backup that was created before the infection took place, and change all passwords that may have been on the infected computer or that were accessible from it. This is the only way to ensure that your system is safe. For more information about security in your organization, contact your system administrator.
Antivirus Protection Dates
- Initial Rapid Release version December 10, 2002
- Latest Rapid Release version September 28, 2010 revision 054
- Initial Daily Certified version December 10, 2002
- Latest Daily Certified version September 28, 2010 revision 036
- Initial Weekly Certified release date December 11, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 0 - 49
- Number of Sites: 0 - 2
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Easy
Damage
- Damage Level: Low
Distribution
- Distribution Level: Low
Writeup By: Neal Hindocha



