Some additonal explanation about the Sasser worms: In summary this worm and its variants exploit vulnerabilies in operating systems Windows 2000/XP/Server 2003 that do not have the security patch MS04-011 installed. The worm does not use email or websites to infect other computers. It does directly infect a computer that is connected to the internet. As part of the exploit the process LSASS.EXE may crash wich can cause the visible symptom with the message about LSA Shell (Export Version).
To remove Sasser from your system you can use the removal descriptions in the links mentioned below. Or you can use an automated recovery tool like McAfee's Stinger or Trend Micro's Damage Cleanup Services (DSC):
Stinger: http://vil.nai.com/vil/sti
DSC: http://www.trendmicro.com/
To prevent similar problems in the future I would recommend to protect internet connected computers with all available MS-patches. MBSA 1.2 (Microsoft Baseline Security Analyzer) is a free application that is able to check your computer whether all necessary patches are installed or not. If not it will list these patches. In addition there will be a link to the corresponding security bulletin where you can download the patch. Running MBSA once a week will make sure that your computer is up to date.
Link to MBSA: http://support.microsoft.c
Virus descriptions about Sasser.A:
CA: http://www3.ca.com/threati
McAfee: http://vil.nai.com/vil/con
Sophos: http://www.sophos.com/viru
Symantec: http://www.symantec.com/av
Trend Micro: http://www.trendmicro.com/
Virus descriptions about Sasser.B:
CA: http://www3.ca.com/threati
McAfee: http://vil.nai.com/vil/con
Sophos: http://www.sophos.com/viru
Symantec: http://www.symantec.com/av
Trend Micro: http://www.trendmicro.com/
Virus descriptions about Sasser.C:
CA: http://www3.ca.com/threati
McAfee: http://vil.nai.com/vil/con
Symantec: http://www.symantec.com/av
Trend Micro: http://www.trendmicro.com/
Main Topics
Browse All Topics





by: ghanaPosted on 2004-05-02 at 22:44:00ID: 10974875
This is a new internet Worm (Sasser.A, Sasser.B, Sasser.C). You need to install the MS security patches to be protected against malware exploiting Windows vulnerabilities. In this case you need to install MS04-011: echnet/sec urity/bull etin/ms04- 011.mspx
http://www.microsoft.com/t