Zusha worm (both A and B variants) were found on September 8th, 2004. Zusha is a network worm that spreads using LSASS (MS04-011) exploit. It also downloads and runs additional files from the Internet. These files are downloaders, they can also kill firewall application processes in memory and modify Windows firewall configuration to bypass the built-in firewall. In addition, a backdoor component is dropped and activated on the infected systems.
Disinfection & Removal
Description Created: 2006-01-01 09:01:38.0
Description Last Modified: 2006-01-01 00:00:00.0