Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Sasser Variant Appears

Suspected virus-writer caught, but creation continues to blaze a path in cyberspace.

David Legard, IDG News Service

  • 0 Yes
  • 0 No

Despite the arrest Friday of the suspected author of the Sasser worm that affected millions of computers worldwide last week, a new variant of the worm appeared Sunday, according to computer security organizations.

This shows that there is an "organized group of delinquents" engaged in creating and distributing these worms, security specialist Panda Software's PandaLabs unit says in a statement.

A German teenager reportedly confessed to creating the Sasser viruses, after being arrested last week.

Similar Tactics

The Sasser.E worm exploits the same Microsoft Windows LSASS vulnerability targeted by its predecessors and has already infected millions of computers, according to PandaLabs. The situation is likely to get worse when company staff return to work after the weekend, PandaLabs says in its statement.

Sasser.E searches the Internet for vulnerable computers and then copies itself to the Windows directory, leading to a systems error which forces the infected computer to reboot every 60 seconds.

Security company McAfee rates the worm low risk, but notes that it attempts to confuse people trying to remove it by adopting a file named (lsasss.exe) which is very similar to a genuine filename present on most systems.

Virus Wars

The same patch that protects against earlier versions of Sasser are also effective against Sasser.E, security experts says.

The Sasser.E worm also tries to remove any instances of the Bagle worm from users' computers, suggesting that there is some rivalry between the virus-writing gangs, according to Panda Labs.

"This seems to indicate that there is a kind of cyber-war being waged among the creators of the Bagle, Mydoom, Netsky, and Sasser worms, and it will continue to cause many more variants of the virus," Panda Labs says in its statement.

  • Recommend this story?
  • 0 Yes
    0 No
 

Featured APC Accessories

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

Sponsored Links