![]() ![]() |
![]() |
|
|
The Short and Skinny of It: Once a system is infected with the worm, Sasser will create a mutex, add a registry key, and open an FTP server on port 5554 to attempt to spread itself by connecting to randomly generated IP addresses on TCP port 445. If a connection is made it will then send shell code to open a remote shell on port 9996. The shell is then used to reconnect to the FTP server on port 5554 to retreive the worm. There are a number of variants of the worm and each has minor deviations from this description.
More Detailed Information:
Microsoft Security Bulletin MS04-011 Fixes by Operating System to prevent the LSASS exploit:
Free Removal Tool:
Preventing Infections of this Nature in the Future:
Need Help?:
|
||||
|
| Network Engineering Services | Networking Capabilities | Data/Voice Cabling Services | Cabling Service Request Form | | PC Services | Data Recovery Services | Logo Design Services | FAQ's | Contact Us | Website Design and Hosting by Craftix Technical Solutions www.craftix.com Email: info@craftix.com © 2004 Craftix Technical Solutions
|
||||