Sophos

W32/Scaner-A

Aliases
  • Exploit-DcomRpc.gen
  • Win32.Agent.Z
  • Win32.Dcom.db
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from September 2004 (3.85)
Protection available since 3 August 2004 11:25:31 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

Download and install the Microsoft patch mentioned above. On standalone computers, update with all relevant security patches from Windows update.

More Information

W32/Scaner-A is a worm that exploits the LSASS vulnerability detailed in MS04-011.

The worm connects to a randomly-generated IP addresses on port 445 and uses the LSASS vulnerability to execute code on the remote computer. This code attempts to download a file from a preconfigured webserver and execute it. At the time of writing, this webserver was not responding.

W32/Scaner-A may report its progress to the author via HTTP POST submissions.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer