Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -5300/2777.5511
 VirusScan Enterprise 8.5i (with Patch 6) - Windows NT/2000/XP/2003
 VirusScan Enterprise 7.1 - Windows NT/2000/XP/2003
 Virex (OS X) Engine/Def - 7.2(v1.1)/081029
 Virex (OS 9.x) Engine/Def - 6.2/071001
 Linux & Solaris Engine/Dat - 5.2.00/4.0.5196
 Symantec Antivirus - 10.1.7.7000
 Symantec Antivirus - 10.2
 Clean Boot 1.0
 Stinger v3.8.0 virus removal tool (Updated 09/10/07)
Current server downloads:
 VirusScan Enterprise 8.5
 VirusScan Enterprise 7.1
 NetShield NetWare - 4.6.2
 NetShield NetWare - 4.6.3
 NetShield NetWare Engine Update - 4.4.00
 ePO agent for NetWare
 ScanMail eManager - 3.0

Information
 ePO 3.0/VirusScan 7.0 Presentation
 Virex 7.x Installation Instructions
 VirusScan FAQs
 VirusScan Instructions
 Additional Resources

Archives
 List of Viruses

Virus Alerts

W32/Sasser.worm and variants updated 5/4/2004, 11:45 AM

A new worm has been detected in the wild and at NIH. It spreads by exploiting a Microsoft Windows vulnerability [MS04-011 vulnerability (CAN-2003-0533)]

The worm spreads with the file name: avserve.exe (w32/Sasser), avserve2.exe (W32/Sasser.b and C) and skynetave.exe (W32/Sasser.d)

Important information from Microsoft regarding this patch is at http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

A side effect of this worm is that it may cause the LSASS.exe process to crash which leads to the machine rebooting.

NAI's Stinger removal tool for W32/Sasser, W32/Sasser.b and W32/Sasser.c is available here

Symantec's removal tool for W32.Sasser (including the "b" and "c" variants) is available here

Microsoft's removal tool for Sasser.A and Sasser.B is available here

For ISSO's and Admins, Retina scanner to search for machines not patched for MS04-011 is available here

NAI has released SuperDat 4357 and later to detect and remove variants of W32/Sasser, w32/Sasser.b, W32/Sasser.c, and W32/Sasser.d.

Symantec released virus definitions 5/3/2004 rev. 22 and later to detect and remove W32/Sasser, W32/Sasser.b, W32/Sasser.c and W32/Sasser.d. Definitions are available through the LiveUpdate feature of Symantec Antivirus.

Additional information is at:

http://www.microsoft.com/security/incident/sasser.mspx from Microsoft
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html from Symantec
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html W32/Sasser.b from Symantec
http://vil.nai.com/vil/content/v_125007.htm from Network Associates
http://vil.nai.com/vil/content/v_125008.htm W32/Sasser.b from Network Associates

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact NIH Help Desk for assistance:
866-319-4357 (toll free), 301-496-4357 (6-HELP) (local), 301-496-8294 (TDD)
http://ithelpdesk.nih.gov/support
Register for iForgotMyPassWord

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers | Privacy Policy

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -