Ovo sam dobio danas od jedne spamerske AV kompanije...konacno nesto dobro od njihovog spama!
ORANGE ALERT
Panda Software reports the appearance of a new network worm: Sasser.A
Only in a few hours, is one of the most detected malicious code by Panda ActiveScan
MADRID, 1 de mayo de 2004
A new network worm has appeared, Sasser.A. This worm exploits the LSASS vulnerability to access the remote systems. This is one of the last vulnerabilities published by Microsoft which affects LSASS (published in the bulletin MS04-011 an available in the following address: http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx). Panda Software has receive numerous incidents due this new worm. Its propagation is on the increase, and right now is one of the most detected by Panda ActiveScan.
It behaviour is similar to Blaster. The worm scans random IP addresses until it finds systems with this vulnerability. Once found, it copies itself in Windows directory with the name AVSERVE.EXE and creates the following registry entry, to ensure it is launched when the system is booted:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avserve.exe = %windir%\avserve.exe
In addition, the vulnerability uses a buffer overflow to make the LSASS.EXE application crash. Because of this, the system can fail.
To prevent incidents with Sasser.A, Panda Software advises users to update their antivirus software and apply the Microsoft patch in order to be protected against this worm. The company has already made the updates to its products available to users to ensure their solutions can detect and eliminate this worm. Similarly, user can also detect and disinfect this and other malicious code using the free, online antivirus, Panda ActiveScan, which is also available on the company's website at: http://www.pandasoftware.com.
More information on this worm and other ones is available in Panda Software's Virus and Intrusions Encyclopedia, at http://www.pandasoftware.com/virus_info/encyclopedia/
Additional information
Vulnerability: Flaws or security holes in a program or IT system, and often used by viruses as a means of infection.
Worm: This is similar to a virus, but it differs in that all it does is make copies of itself (or part of itself).
More technical terms available on: http://www.pandasoftware.com/virus_info/glossary
Ovo znaci da treba da mu ga date po windows update stranici, vidim da je M$ izbacio u poslednja 2-3 dana cak 3 nova patcha. Za Win2k to su patchevi KB837001, KB828741 i KB835732, a za XP se snadjite 🙂.
ORANGE ALERT
Panda Software reports the appearance of a new network worm: Sasser.A
Only in a few hours, is one of the most detected malicious code by Panda ActiveScan
MADRID, 1 de mayo de 2004
A new network worm has appeared, Sasser.A. This worm exploits the LSASS vulnerability to access the remote systems. This is one of the last vulnerabilities published by Microsoft which affects LSASS (published in the bulletin MS04-011 an available in the following address: http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx). Panda Software has receive numerous incidents due this new worm. Its propagation is on the increase, and right now is one of the most detected by Panda ActiveScan.
It behaviour is similar to Blaster. The worm scans random IP addresses until it finds systems with this vulnerability. Once found, it copies itself in Windows directory with the name AVSERVE.EXE and creates the following registry entry, to ensure it is launched when the system is booted:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avserve.exe = %windir%\avserve.exe
In addition, the vulnerability uses a buffer overflow to make the LSASS.EXE application crash. Because of this, the system can fail.
To prevent incidents with Sasser.A, Panda Software advises users to update their antivirus software and apply the Microsoft patch in order to be protected against this worm. The company has already made the updates to its products available to users to ensure their solutions can detect and eliminate this worm. Similarly, user can also detect and disinfect this and other malicious code using the free, online antivirus, Panda ActiveScan, which is also available on the company's website at: http://www.pandasoftware.com.
More information on this worm and other ones is available in Panda Software's Virus and Intrusions Encyclopedia, at http://www.pandasoftware.com/virus_info/encyclopedia/
Additional information
Vulnerability: Flaws or security holes in a program or IT system, and often used by viruses as a means of infection.
Worm: This is similar to a virus, but it differs in that all it does is make copies of itself (or part of itself).
More technical terms available on: http://www.pandasoftware.com/virus_info/glossary
Ovo znaci da treba da mu ga date po windows update stranici, vidim da je M$ izbacio u poslednja 2-3 dana cak 3 nova patcha. Za Win2k to su patchevi KB837001, KB828741 i KB835732, a za XP se snadjite 🙂.