|
|||||
| Support: Security: PC Sentry: Sasser | |||||
|
name: Sasser aka: W32.Sasser@mm type: Worm host platform: Windows 2000, XP, Server 2003 first incidence: April 30, 2004 level of incidence: High damage capacity: High Links: Symantec - W32.Sasser, Symantec - W32.Sasser.B, Symantec - W32.Sasser.C McAfee - W32.Sasser, McAfee - W32.Sasser.B Unlike many worms, Sasser does not spread by emails. Sasser attacks through a software bug found in the Microsoft Operating System. The software bug is documented here. Users are encouraged to apply patch to their Windows Operating System through the Windows Update facility. Other than installing patches, users who run firewalls are also encouraged to block incoming TCP port 5554, 9996, and 445. A successful exploit will grant attackers full access to the victims' computers. The worm is known to setup FTP server at port 5554 and also altered a windows API to inhibit users' attempt to shut down and restart his/her PC. The Worm has mutated since its initial release. The latest mutation is W32.Sasser.C. Symantec has developed removal tools for Sasser variants. The removal instructions and tools can be found here. If you believe you have become infected
or have any questions regarding worm, please do not hesitate to
contact us.
As always, as a Green Apple user you are welcome to bring in your
computer for us to examine and, where possible, fix. |
|||||
|
|