|
|
Virus Warning: W32.Sasser.B.Worm
2004-04-30
W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly-chosen IP addresses for vulnerable systems.
Notes:
- The MD5 hash value for this worm is 0x1A2C0E6130850F8FD9B9B5309413CD00.
- Symantec Security Response has developed a removal tool to clean the infections of W32.Sasser.B.Worm.
- Block TCP ports 5554, 9996 and 445 at the perimeter firewall and install the appropriate Microsoft patch (MS04-011) to prevent remote exploitation of the vulnerability.
We recommend you get the removal tool at http://www.symantec.com
|