F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Sasser.E

[Summary] | [Disinfection] | [Detection]



NAME:Sasser.E
ALIAS:W32/Sasser.E, LSASSS
SIZE:15872

Summary

Sasser.E is an Internet worm spreading through the MS04-011 (LSASS) vulnerability.

Sasser.E is a variant of Sasser.D.

It has been modified by changing the main virus file name to LSASSS.EXE. Note that this has nothing to do with Windows' LSASS.EXE. Also the port numbers used for the shell and FTP server have been changed.

Also, Sasser.E tries to remove the Bagle worm, unlike earlier Sassers but just like many Netsky variants.

Two hours after infection Sasser.E displays the following message:

For more details on Sasser, see description of Sasser.D:

http://www.f-secure.com/v-descs/sasser_d.shtml

Disinfection

F-Secure has developed a special disinfection tool which can find and remove all the known Sasser variants.

The tool is available from the following locations:

ftp://ftp.f-secure.com/anti-virus/tools/f-sasser.zip
ftp://ftp.f-secure.com/anti-virus/tools/f-sasser.exe
ftp://ftp.f-secure.com/anti-virus/tools/f-sasser.txt

or through HTTP:

http://www.f-secure.com/tools/f-sasser.zip
http://www.f-secure.com/tools/f-sasser.exe
http://www.f-secure.com/tools/f-sasser.txt

Before using the tool please read the disinfection instructions from 'f-sasser.txt'.

Manual Disinfection

To manually disinfect an infected system, first apply the Microsoft patch MS04-011, then use Task Manager to kill the "lsasss.exe" process, then delete the file 'lsasss.exe' from your Windows directory and reboot.

For step-by-step instructions, see Microsoft's site:
http://www.microsoft.com/security/incident/sasser.asp#steps

Back to the Top


Detection

Detection in F-Secure Anti-Virus was published on May 9th, 2004 in update:

[FSAV_Database_Version]

Version=2004-05-09_01

Back to the Top


Description Updated: Jarno Niemela, May 9th, 2004

Write-up: Mikko Hypponen, May 9th, 2004

F-Secure Corporation, May 9th, 2004