Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Zusha


Aliases:


Worm.Win32.Zusha.b
TrojanDownloader.Win32.Agent.co
Trojan.Win32.Small.aq
Worm.Win32.Zusha.a

Malware
Virus
W32

Summary

Zusha worm (both A and B variants) were found on September 8th, 2004. Zusha is a network worm that spreads using LSASS (MS04-011) exploit. It also downloads and runs additional files from the Internet. These files are downloaders, they can also kill firewall application processes in memory and modify Windows firewall configuration to bypass the built-in firewall. In addition, a backdoor component is dropped and activated on the infected systems.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.







Description Created: 2006-01-01 09:01:38.0
Description Last Modified: 2006-01-01 00:00:00.0



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.