Digital Edition

SYS-CON.TV
Sasser: Microsoft Offers Removal Tool, Seeks Worm Source
Sasser: Microsoft Offers Removal Tool, Seeks Worm Source

A recent increase in malicious activity on the Internet, including the development of attack tools and exploit code, has resulted in an automated attack against computer users in the form of a worm identified as "W32.Sasser.worm" ("Sasser"). Through this worm, the attacker is attempting to exploit systems that are not protected against the Local Security Authority Subsystem Service (LSASS) vulnerability, which is mitigated by the use of a firewall and fixed in Microsoft Security Update MS04-011 on April 13, 2004. There is additional malicious activity in the form of variants of a worm known as "Agobot" (or "Agrobot"), which similarly seeks to exploit systems not protected by a firewall or the installation of MS04-011.

In a bulletin, the McAfee division of Network Associates, Inc. describes Sasser as "a self-executing worm that spreads by exploiting the Microsoft MS04-011 vulnerability. The primary purpose of the worm seems to be to spread to as many vulnerable machines as possible by exploiting un-patched Windows systems, giving it the ability to execute without requiring any action on the part of the user. Once activated the worm copies itself to a folder in the Windows System directory and adds a registry run key to load at system start-up."

Microsoft is working closely with law enforcement authorities, including the Northwest CyberCrime Taskforce, a joint effort between the FBI and U.S. Secret Service, to forensically analyze the malicious code in Sasser and Agobot, to identify and bring to justice those responsible for this malicious activity. The investigation is ongoing, and questions about the investigation should be referred to the Northwest CyberCrime Taskforce.

At the same time, Microsoft is working closely with the anti-virus community and other industry partners to help protect our customers. Customers using a firewall-- including the firewall in Windows XP, as well as third-party hardware or software firewalls -- are generally protected against the Sasser and Agobot threats. Customers can protect against these attacks by first ensuring that their firewall is in place, and then installing Microsoft Security update MS04-011 immediately. The MS04-011 security bulletin is available as a free download or users can use Windows Update to access the latest security update.

In addition, Microsoft has made a no-cost, software-based cleaner tool available that customers can use to automatically remove the Sasser worm from infected PCs after deploying the security update.

Customers who have followed the steps on www.microsoft.com/protect to enable Automatic Updates should already be protected against these emerging threats, as they should have received MS04-011 automatically. Microsoft continues to recommend that all customers visit www.microsoft.com/protect to take three key steps to protect their PCs. These include:

  • Use an Internet Firewall on all PCs and Laptops: An Internet firewall can help prevent outsiders from getting to your computer through the Internet. If you use Microsoft Windows XP, enable the built-in firewall.
  • Update Your Computer: Windows includes the automatic updates feature (Windows Update) which can automatically download the latest Microsoft security updates. Windows 98 SE and Windows ME can be updated from windowsupdate.microsoft.com.
  • Use Up-to-Date Antivirus Software: Installing, configuring and maintaining antivirus protection is absolutely essential.

    Immediate information and cure for this worm can also be found online at the Network Associates McAfee AVERT site. McAfee AVERT is advising its customers to update to the 4355 DATs to stay protected

    About Security News Desk
    SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.

  • In order to post a comment you need to be registered and logged in.

    Register | Sign-in

    Reader Feedback: Page 1 of 1



    ADS BY GOOGLE
    Subscribe to the World's Most Powerful Newsletters

    ADS BY GOOGLE

    Everyone wants the rainbow - reduced IT costs, scalability, continuity, flexibility, manageability, ...
    Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT...
    The standardization of container runtimes and images has sparked the creation of an almost overwhelm...
    SYS-CON Events announced today that DatacenterDynamics has been named “Media Sponsor” of SYS-CON's 1...
    Most DevOps journeys involve several phases of maturity. Research shows that the inflection point wh...
    Dynatrace is an application performance management software company with products for the informatio...
    Today, we have more data to manage than ever. We also have better algorithms that help us access our...
    Andi Mann, Chief Technology Advocate at Splunk, is an accomplished digital business executive with e...
    Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: D...
    DevOpsSummit New York 2018, colocated with CloudEXPO | DXWorldEXPO New York 2018 will be held Novemb...
    DXWorldEXPO LLC announced today that ICOHOLDER named "Media Sponsor" of Miami Blockchain Event by Fi...
    @DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22...
    SYS-CON Events announced today that IoT Global Network has been named “Media Sponsor” of SYS-CON's @...
    To Really Work for Enterprises, MultiCloud Adoption Requires Far Better and Inclusive Cloud Monitori...
    The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news an...
    CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018,...
    DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing w...
    Disruption, Innovation, Artificial Intelligence and Machine Learning, Leadership and Management hear...
    "We host and fully manage cloud data services, whether we store, the data, move the data, or run ana...
    Enterprises are striving to become digital businesses for differentiated innovation and customer-cen...