Summary

Summary
Action
More Information
| Included in our products from | September 2004 (3.85) |
|---|---|
| Protection available since | 3 August 2004 11:25:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Download and install the Microsoft patch mentioned above. On standalone computers, update with all relevant security patches from Windows update.
More Information
W32/Scaner-A is a worm that exploits the LSASS vulnerability detailed in MS04-011.
The worm connects to a randomly-generated IP addresses on port 445 and uses the LSASS vulnerability to execute code on the remote computer. This code attempts to download a file from a preconfigured webserver and execute it. At the time of writing, this webserver was not responding.
W32/Scaner-A may report its progress to the author via HTTP POST submissions.
