Page 1 of 1

Sasser Worm (01/05/04)

Posted: Sun May 02, 2004 12:14 pm
by quicksilver
This worm is currently doing the rounds... :( it will infect your machine via an open port usually 455.. then broadcast itself to other ip address which it generates. It will also makes a selection of copies of itself (8 jumbled letters) in your windows folder. (typically C:\ LFGCIOBL.exe, YEQKZPBY.exe). Sasser works in conjunction with another nastier virus
W32GaoboT!INF this ones a meanie, it will disable your anti viral software , leaving you open to everything the web can send you :evil: .
Both of these two have variants already! Usual preventive options ie update your antiviral package regularly , microsoft update , and only let known applications through your firewall using only the ports they need to work. Help with these 2 can be found at sysmantec. (norton) :D
http://securityresponse.symantec.com/av ... .tool.html
http://securityresponse.symantec.com/av ... .tool.html

Posted: Sun May 09, 2004 6:13 am
by battye
What does the virus do? :(

Posted: Sun May 09, 2004 1:12 pm
by Bacon
Sasser is a new worm which will constantly shut down your computer and boot it back up again. As long as your Windows Updates are all up to date your protected.

Posted: Sun May 09, 2004 2:29 pm
by battye
I ran it today and it said there were no critical updates :?

Posted: Mon May 10, 2004 2:17 am
by quicksilver
You can read about it here , (this is the B variant but it discusses the normal one as well ) http://securityresponse.symantec.com/av ... .worm.html Basically it will eat up your resources. Its not a file damager. and if you have updated on certain microsoft packages you may never even see this one : )