Sasser.C is an Internet worm spreading through the MS04-011 (LSASS) vulnerability.
If the infection is in a local network, please follow the instructions on this webpage:
To manually disinfect an infected system, first apply the Microsoft patch MS04-011, then use Task Manager to kill the "avserve2.exe" process, then delete the file AVSERVE2.EXE from your Windows directory and reboot. For step-by-step instructions, see Microsoft's site: https://www.microsoft.com/security/incident/sasser.asp#steps
Find the latest advice in our Community Knowledge Base.
See the manual for your F-Secure product on the Help Center.
Submit a file or URL for further analysis.
Sasser.C is a variant of Sasser.B, with identical length. Main difference is that this version starts 1024 processes to scan for new vulnerable hosts, instead of 128 processes.
For more details, see the description of Sasser.B