W32.Sasser.Worm
W32.Sasser is a worm that attempts to send code that exploits the MS04-011 vulnerability.
The worm spreads by randomly scanning IP addresses for vulnerable systems.
The presence of the following files is an indication of infection:
%windows%\avserve.exe
The worm then adds one of the following registry values:
"avserve.exe"=%windows%\avserve.exe
To the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The worm opens FTP port 5554, and randomly scans IP addresses for vulnerable systems.
Symantec Security Response is continuing to analyze the worm and will update this page as information becomes available.
--------------------------------------------------------------------------------
Note: Rapid Release virus definitions, version 30/04/04 rev 70 (20040430.070) and greater, detect this threat.
病毒名稱是這個
那先是我去諾頓他說的
但是看不懂
而且無法刪除
請電腦厲害的教一下吧~!!
現在電腦會出現倒數重開機(跟之前那個病毒一樣,但只是偶爾)
連線一下子後會斷線,一定要重開或是登出再進入才可以上網
會lag
現在有出現這些問題...
請幫幫忙吧~~~