The Sasser-B Worm is a network based, C++ written worm, very similar to the Sasser-A Worm. It spreads through a vulnerability in the Local Security Authority Subsystem (LSASS). Infection of the worm causes excessive network traffic and a slow-down of the system. Sasser-B will copy itself to the windows directory, calling itself "avserve2.exe".
- Run REGEDIT and delete the key:
- Run Vbuster.Exe and use it to delete all occurances of the worm