( W32.SQLExp.Worm , W32/SQL.Slam.A)
The BitDefender Virus Analyse Team has releasead a free removal tool for this particular virus. Click here in order to download this tool.
Sorin Victor Dudea
BitDefender Virus Researcher
This is an Internet worm that spreads using a known vulnerability in MS SQL Server. For more information about this vulnerability go to:
It arrives as a malformed 376 bytes packet. It uses a stack overflow exploit to execute itself. After its code is executed it generates random IP numbers based on GetTickCount function and sends itself to those addresses using UDP port 1434. Because the worm send itself continuously it generates Denial Of Service.
To remove this vulnerability, install the following patch: