Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Sasser.G


Aliases:


Sasser.G
Worm.Win32.Sasser.gen

Malware
Worm
W32

Summary

Sasser.G is a minor modification of the Sasser.F worm. It shares most of its code and functionality, although it uses a different filename when copying itself into the system and a different mutex name.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details


System Infection

When the worm enters the system it creates a copy of itself in the Windows Directory as 'avserve3.exe'. This copy is added to the Registry as

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  "avserve3.exe" = "%WinDir%\avserve3.exe"


It creates mutexes named 'PinaasoSky' and 'Jobaka3'.



Detection

Detection in F-Secure Anti-Virus was published on May 14th, 2004 in update:

Detection Type: PC
Database: 2004-05-14_01



Technical Details: Ero Carrera, August 23rd, 2004



Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Disinfect your PC




F-Secure Anti-Virus will disinfect your PC and remove all harmful files