Computing.Net > Forums > Security and Virus > Sasser Worm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Sasser Worm

Reply to Message Icon

Name: Abnormal
Date: May 1, 2004 at 11:48:55 Pacific
OS: n/a
CPU/Ram: n/a

Sponsored Link
Ads by Google

Response Number 1
Name: mtlieb
Date: May 1, 2004 at 12:03:12 Pacific
Reply:

Thanks Abnormal... here we go again!

There's already starting to be a ton of posts in the XP forum about lsass.exe shutdowns, and it's going to be the same as Blaster i'm afraid. Once again, if people had just downloaded the critical updates and enabled a firewall (even just the XP firewall), they'd not be vulnerable.

It's frustrating.

Oh well :)


0

Response Number 2
Name: Wombat
Date: May 1, 2004 at 12:24:32 Pacific
Reply:

This Win XP patch was dated 13.04.2004 so their is no excuses really.

http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx

Iligitimi non carborundum est


0

Response Number 3
Name: Wombat
Date: May 1, 2004 at 12:29:30 Pacific
Reply:

That should read "released" instead of dated.

Iligitimi non carborundum est


0

Response Number 4
Name: aosclay
Date: May 1, 2004 at 13:20:59 Pacific
Reply:

Thanks Abnormal,

now at least I know what my Monday is going to be like.

:)

Long live the Fighters

AOSCLAY


0

Response Number 5
Name: Abnormal
Date: May 1, 2004 at 19:26:50 Pacific
Reply:

The removal tools are out.
W32.Sasser Removal Tool

Stinger



0

Related Posts

See More



Response Number 6
Name: mtlieb
Date: May 1, 2004 at 20:02:56 Pacific
Reply:

I'm seeing a number of posts from folks having problems with avserve2.exe but I haven't seen this file discussed in any of the Sasser technical bulletins (only avserve.exe is mentioned). Does anyone know anything about this? Is it also removed with the Sasser tools, or is this some variant not covered yet? Thanks :)


0

Response Number 7
Name: Abnormal
Date: May 1, 2004 at 20:29:26 Pacific
Reply:

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html

I have seen both in a hijackthis log,
not sure if the removal tool finds both.


0

Response Number 8
Name: Frenchie
Date: May 2, 2004 at 08:10:35 Pacific
Reply:


Hi Abnormaal, Jim, Wombat, aosclay, mtlieb, hi everybody,

See this thread -> is this blast worm?! and especially:
- 2 variants Sasser and Sasser.B
- Removal tool by Symantec
- 3 patches by Microsoft

Good luck!

Have a good day,
Gérard from Paris, France


0

Response Number 9
Name: Abnormal
Date: May 2, 2004 at 19:07:06 Pacific
Reply:

Updates are a good thing, get it now!

http://v4.windowsupdate.microsoft.com


0

Response Number 10
Name: boot
Date: May 2, 2004 at 23:47:46 Pacific
Reply:

hey folks just to let eveyone know there is a sasserworm C and other variables of A

semantec has the new definitions for it to be removed
but should scan with your ad aware and spybot cause theres stuff stil creeping up


0

Response Number 11
Name: svg
Date: May 3, 2004 at 01:39:20 Pacific
Reply:

I thought I'd include the link below, because there was someone who complained about losing internet connectivity after applying the sasser-fixes.

Although I'm not sure that was related to the worm itself, it may proove very handy to download the .zip first, just in case.

WinSockFix.zip (RefBy Tufenuf)
___________________________________________
[Belgium, GMT+1]_________________________svg


0

Response Number 12
Name: Chriswok
Date: May 3, 2004 at 02:00:30 Pacific
Reply:

Hey I've followed the steps on the Microsoft site and as far as I know removed it, yet I still have problems.

1. When I start up the following sites try to connect to the internet:

ityoill1goto.ygto.com
agfprrpfml.mykgb.com
host1liil1.mooo.com
1liil1liil1.afraid.org
till1liil1.afraid.org
thisisliil1.b3ta.org
imiill11lnot.afraid.org
user1l1l.a-p-e.m-a-f-i-a.com
l.1ove.you.oil1y.afraid.org
il1l.d0.hear.a1l.mooo.com
hplph0pfiipf10p.afraid.org
1l2li.0n.my.ignorelist.com
ftp.binary01o100li.ygto.com
l1l1il1i.y20o3zuxx.xxuz.com

2. The task manager has been covered over, so I can no longer see what processes are running and can't see them to shut them down.

3. I can't access any website or folder with the word Virus in the header.

4. Trying to install an anti virus the screen gets flooded during the installation with the 'are you sure you want to quit setup screen'

Please help,

Cheers,

Chris


0

Response Number 13
Name: Vulture
Date: May 3, 2004 at 03:14:48 Pacific
Reply:

I've lost my internet connection on my home computer. I don't even know how to download those removers. I'm kinda posting this from somewhere else.

I'm lost. I can't even acess the internet. When i dial up then it is connected to internet but i can't acess any websites at all.

How do i get rid of a Sasser worm? My computer has been infected with the worm called Sasser. And i wonder how i can get rid of it.


0

Response Number 14
Name: aosclay
Date: May 3, 2004 at 06:26:19 Pacific
Reply:

hey Chriswok and Vulture...

If you have taken care of your Sasser Worm problems, please create your own posts outlining your problems in the security and virus forum.

VULTURE: TRY THIS FIRST

LSPFix

if this does not work, come back for more help.

GOOD LUCK!


AOSCLAY


0

Response Number 15
Name: Lee DX
Date: May 3, 2004 at 06:33:45 Pacific
Reply:

I recommend downloading 'STINGER' it will scan for 41 different current worms and virus's. BE SURE TO READ THE INFO IF YOUR ARE USING WINXP or ME. Check up on 'STINGER' UPDATES OFTEN.

Info if you are running WinXP or ME:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

'STINGER' DOWNLOAD:
http://vil.nai.com/vil/stinger/

GOOD LUCK -
LEE

P.S. YOU MIGHT ALSO UP YOUR SECURITY AND PRIVACY SETTINGS: RIGHT CLIK MY COMPUTER, THEN CLIK PROPERTIES, THEN THE SECURITY TAB, READ AND RESET THE CONFIGURATION TO MEDIUM HIGH FOR STARTS. ALSO, GET YOUR 'CRITICAL' WINDOWS UPDATES HERE: http://windowsupdate.microsoft.com/

GET A GOOD ANTIVIRUS PROGRAM, AVG FREE EDITION, IF YOU HAVE NOTHING - http://www.grisoft.com/ AND KEEP THE DEFINATIONS UPDATED EVERYDAY - LOTS OF LUCK


0

Response Number 16
Name: johnny blaze22
Date: May 3, 2004 at 14:22:37 Pacific
Reply:

i cannot get my computer to reboot, not even in safe mode it goes to a screen that says unable to load hive file. Any suggestions.


0

Response Number 17
Name: Virginia
Date: May 3, 2004 at 16:48:24 Pacific
Reply:

I've just cleaned this virus from my system. However, I couldn't edit my registry, start anti-virus programs, and something was constantly trying to connect to the net. The only way to stop the interference was to hit END PROCESS on microsoft.exe in Windows Task Manager. I hope this helps someone in the same boat.


0

Response Number 18
Name: Cristian_ar
Date: May 3, 2004 at 16:50:09 Pacific
Reply:

I got the A and B varieties of sasser on Friday night. As far as I know, I've succesfullly removed them using the Symantec and McAffe fix tools (at least the files everybody is talking about are no longer there), but my system still remains painfully slow and there are frequent rebootings...anyone else with the same problem? any suggestions?


0

Response Number 19
Name: Johnw
Date: May 3, 2004 at 17:02:13 Pacific
Reply:

johnny , see if this helps .

http://support.microsoft.com/?kbid=307545


0

Response Number 20
Name: dirkhaim
Date: May 4, 2004 at 13:48:19 Pacific
Reply:

I came home the other day to find my computer shutting down on tiself and giving me a one minute times. After a quick research I installed two updates from Microsoft, and the shuting down problem disappeared. Afterwards I ran some scanning apps to check for viruse (including Mcafee, Syamntec and the Sasser detection tool by Microsoft), and all reported my computer to be clean. I also ran a full system scan in safe mode with my updated NAV. So far so good. Sasser disabled my NAV which I manually re-enabled. But after I restart my computer my NAV is disabled, everytime. And I everytime I get the Sasser error message, something about LSAP. Nothing happens besides it, and NAV claims my comptuer to be clean. What can I do to get rid of these after effects? And what can I do to make sure my comptuer is REALLY clean?

Thanks.


0

Response Number 21
Name: road_warrior_1977
Date: May 4, 2004 at 23:06:49 Pacific
Reply:

heres a problem solver for this new sasser worm crap,if you dont already have it download avg 6.0 free version and update it after you download it,if you have the sasser worm it will kill it.i know because ive had to do it so there you go good luck.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Sasser Worm

Like SASSER WORM...but not! www.computing.net/answers/security/like-sasser-wormbut-not/14722.html

Sasser worm www.computing.net/answers/security/sasser-worm/15162.html

Can't remove II-worm Sasser ?? Hel www.computing.net/answers/security/cant-remove-iiworm-sasser-hel/11452.html