Sasser Worm (01/05/04)
Posted: Sun May 02, 2004 12:14 pm
This worm is currently doing the rounds...
it will infect your machine via an open port usually 455.. then broadcast itself to other ip address which it generates. It will also makes a selection of copies of itself (8 jumbled letters) in your windows folder. (typically C:\ LFGCIOBL.exe, YEQKZPBY.exe). Sasser works in conjunction with another nastier virus
W32GaoboT!INF this ones a meanie, it will disable your anti viral software , leaving you open to everything the web can send you
.
Both of these two have variants already! Usual preventive options ie update your antiviral package regularly , microsoft update , and only let known applications through your firewall using only the ports they need to work. Help with these 2 can be found at sysmantec. (norton)
http://securityresponse.symantec.com/av ... .tool.html
http://securityresponse.symantec.com/av ... .tool.html
W32GaoboT!INF this ones a meanie, it will disable your anti viral software , leaving you open to everything the web can send you
Both of these two have variants already! Usual preventive options ie update your antiviral package regularly , microsoft update , and only let known applications through your firewall using only the ports they need to work. Help with these 2 can be found at sysmantec. (norton)
http://securityresponse.symantec.com/av ... .tool.html
http://securityresponse.symantec.com/av ... .tool.html