Zusha worm (both A and B variants) were found on September 8th, 2004. Zusha is a network worm that spreads using LSASS (MS04-011) exploit. It also downloads and runs additional files from the Internet. These files are downloaders, they can also kill firewall application processes in memory and modify Windows firewall configuration to bypass the built-in firewall. In addition, a backdoor component is dropped and activated on the infected systems.
Disinfection & Removal
Allow F-Secure Anti-Virus to disinfect the relevant files.
For more general information on disinfection, please see Removal Instructions.
Description Created: 2006-01-01 09:01:38.0
Description Last Modified: 2006-01-01 00:00:00.0