The Sasser-A Worm is a network based, C++ written worm. It spreads through a vulnerability in the Local Security Authority Subsystem (LSASS). Infection of the worm causes excessive network traffic and a slow-down of the system. Sasser-A will copy itself to the windows directory, calling itself "avserve.exe".
REMOVAL INSTRUCTIONS:
- Run REGEDIT and delete the key:
- avserve.exe
in location:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- Run Vbuster.Exe and use it to delete all occurances of the worm