- August 2, 2002
- February 13, 2007 11:40:00 AM
W32.Golsys.8020 is a multi-threaded Win32 virus. When executed, it creates the file %system%\Sysl0gon.exe. The virus will also attempt to infect all executable files that it can find, both on the local hard drive and on mapped drives.
NOTE: %system% is a variable. The virus locates the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). The worm copies itself to that location.
Definitions dated prior to August 2, 2002 detect this virus as BloodHound.W32.1.
Antivirus Protection Dates
Initial Rapid Release version August 2, 2002
Latest Rapid Release version September 28, 2010 revision 054
Initial Daily Certified version August 2, 2002
Latest Daily Certified version September 28, 2010 revision 036
Initial Weekly Certified release date August 7, 2002
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Neal Hindocha