Threat Description

Zusha

Details

Aliases: Worm.Win32.Zusha.b, TrojanDownloader.Win32.Agent.co, Trojan.Win32.Small.aq, Worm.Win32.Zusha.a
Category: Malware
Type: Virus
Platform: W32

Summary



Zusha worm (both A and B variants) were found on September 8th, 2004. Zusha is a network worm that spreads using LSASS (MS04-011) exploit. It also downloads and runs additional files from the Internet. These files are downloaders, they can also kill firewall application processes in memory and modify Windows firewall configuration to bypass the built-in firewall. In addition, a backdoor component is dropped and activated on the infected systems.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More