Chris Posted May 1, 2004 Report Share Posted May 1, 2004 update A worm, dubbed Sasser by antivirus firms, was spreading slowly throughout the Internet on Saturday, taking advantage of a vulnerability in unpatched Windows systems to infect new hosts.The Sasser worm began spreading Friday night and seems to be moving at a pace far slower than previous worms such as MSBlast and Code Red, said Alfred Huger, senior director of security firm Symantec's response team."It is a slow burn," he said. "It is picking up speed, but right now we aren't seeing to much activity."Symantec initially rated the Sasser worm as a two on its five-point scale of threats. A five is the highest danger rating on the scale. Rival antivirus firm Network Associates rated the threat a medium danger, and the Internet Storm Center, which monitors network threats, raised its general Internet danger level to yellow, essentially a medium rating as well.More | Here Quote Link to comment Share on other sites More sharing options...
Boris Posted May 1, 2004 Report Share Posted May 1, 2004 Products Affected by This Worm Windows 2000 Service Pack 2, Windows 2000 Service Pack 3, and Windows 2000 Service Pack 4 Windows XP and Windows XP Service Pack 1 Windows XP 64-bit Edition Service Pack 1 Products Not Affected by This Worm Windows NT 4.0 Service Pack 6a Windows XP 64-Bit Edition Version 2003 Windows Server 2003 Windows Server 2003 64-Bit EditionHow to Tell If Your Computer Is InfectedIf your computer is infected with W32.Sasser.worm, you may see a dialog box with text that refers to LSASS.exe. Some customers whose computers have been infected may not notice the presence of the worm at all, while others who are not infected may experience problems because the worm is attempting to attack their computer. Typical symptoms may include systems rebooting every few minutes without user input.Preventive Steps for Home UsersCustomers can protect against this worm by installing Microsoft Security Update MS04-011 immediately. If you have a computer with Windows XP and have enabled the Windows XP Firewall, you are protected from attacks by this worm. Also, most third-party firewalls will block this attack. If you do not have the Windows XP Firewall enabled or a third-party firewall set up, please take the recommended basic precautions when connecting to the Internet to make your personal computer more resistant to this type of attack:http://www.microsoft.com/security/incident/sasser.asp Quote Link to comment Share on other sites More sharing options...
expertec Posted May 2, 2004 Report Share Posted May 2, 2004 Thanks you two, I'm getting the patch right now, but I have a firewall so it would not affect me anyway??? Quote Link to comment Share on other sites More sharing options...
Boris Posted May 2, 2004 Report Share Posted May 2, 2004 AVG + a squared now updated to detect it as well Quote Link to comment Share on other sites More sharing options...
Boris Posted May 2, 2004 Report Share Posted May 2, 2004 Microsoft Sasser.A & .B Worm Removal Tool A situation has been identified where the Sasser.A or Sasser.B worms could have infected some systems before the application of MS04-011 [KB835732]. This tool will help remove the Sasser.A and Sasser.B worms from these systems. For systems with MS04-011 [KB835732], no further action is needed once this tool is installed. Install this tool to help remove this worm from your PC.http://www.majorgeeks.com/download4212.html Quote Link to comment Share on other sites More sharing options...
mark2 Posted May 3, 2004 Report Share Posted May 3, 2004 As of May 2, 2004 10:07 PM (PST), TrendLabs has declared a High Risk Virus alert to control the spread of WORM_SASSER.B. Several infection reports have been received indicating that this worm is spreading in the Latin American region.This variant of WORM_SASSER.A similarly exploits the Windows “Local Security Authority Subsystem Service” (LSASS) vulnerability, which is a buffer overrun that allows remote code execution and enables an attacker to gain full control of the affected system. • http://www.trendmicro.com/vinfo/virusencyc...CROSOFT_WINDOWS• http://www.microsoft.com/technet/security/...n/ms04-011.mspxSeems to be picking up momentum as blaster did Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.