What You Should Know About the Sasser Worm and Its Variants
Published: May 1, 2004 | Updated: May 2, 2004 - 3:30 P.M. Pacific Time
Microsoft teams have confirmed that the Sasser worm (W32.Sasser.A
and its variants) is currently circulating on the Internet. Microsoft
has verified that the worm exploits the Local Security Authority
Subsystem Service (LSASS) issue that was addressed by the security
update released on April 13 in conjunction with Microsoft Security Bulliten MS04-011.
To protect your computer against Sasser and its variants, do the following:
Before you take other steps, make sure you have a firewall activated
to help protect your computer against infection. If you have a hardware
firewall in place for your home or workplace connection, or if you use
the firewall included with Microsoft® Windows® XP, the Sasser worm is
most likely blocked. If your computer has been infected, activating
firewall software will help limit the effects of the worm on your
computer. For comprehensive guidance to installing and enabling a
firewall, see the Microsoft Protect Your PC site.
To help protect your computer against the Sasser worm and its
variants, you must first download and install security update 835732,
which was released with Microsoft Security Bulletin MS04-011. You can
find update 835732 on the Windows Update Web site
listed in the Critical Updates and Service Packs section. You can also
download and install this update manually from the Microsoft.com
Download Center. To find the download for your operating system, refer
to Technical Security Bulletin MS04-011.
Note If you installed the updates for MS04-011
manually or through Automatic Updates before Friday, April 30, then you
are already protected against this issue.
You can use this tool to search your hard disk for and try to remove Sasser.A and Sasser.B. To do so, click Check My PC for Infection.
Important To use this tool, you must be running Windows XP or Windows 2000, and you must have already installed the update released with Microsoft Security Bulletin MS04-011.
If the scanning and cleaning tool does not work for you, try using
one of the free worm removal tools available at these antivirus
software vendors' Web sites:
If you prefer to remove the worm manually (for advanced users only), see the Microsoft Product Support Services (PSS) Security Response Team alert for technical guidance.
To help protect your computer against a wide variety of security threats, see Protect Your PC.
|