Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Thanks Abnormal... here we go again!
There's already starting to be a ton of posts in the XP forum about lsass.exe shutdowns, and it's going to be the same as Blaster i'm afraid. Once again, if people had just downloaded the critical updates and enabled a firewall (even just the XP firewall), they'd not be vulnerable.
It's frustrating.
Oh well :)

This Win XP patch was dated 13.04.2004 so their is no excuses really.
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
Iligitimi non carborundum est

Thanks Abnormal,
now at least I know what my Monday is going to be like.
:)
Long live the Fighters
AOSCLAY

I'm seeing a number of posts from folks having problems with avserve2.exe but I haven't seen this file discussed in any of the Sasser technical bulletins (only avserve.exe is mentioned). Does anyone know anything about this? Is it also removed with the Sasser tools, or is this some variant not covered yet? Thanks :)

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
I have seen both in a hijackthis log,
not sure if the removal tool finds both.

Hi Abnormaal, Jim, Wombat, aosclay, mtlieb, hi everybody,See this thread -> is this blast worm?! and especially:
- 2 variants Sasser and Sasser.B
- Removal tool by Symantec
- 3 patches by MicrosoftGood luck!
Have a good day,
Gérard from Paris, France

hey folks just to let eveyone know there is a sasserworm C and other variables of A
semantec has the new definitions for it to be removed
but should scan with your ad aware and spybot cause theres stuff stil creeping up

I thought I'd include the link below, because there was someone who complained about losing internet connectivity after applying the sasser-fixes.
Although I'm not sure that was related to the worm itself, it may proove very handy to download the .zip first, just in case.
▫ WinSockFix.zip (RefBy Tufenuf)
___________________________________________
☺ [Belgium, GMT+1]_________________________svg

Hey I've followed the steps on the Microsoft site and as far as I know removed it, yet I still have problems.
1. When I start up the following sites try to connect to the internet:
ityoill1goto.ygto.com
agfprrpfml.mykgb.com
host1liil1.mooo.com
1liil1liil1.afraid.org
till1liil1.afraid.org
thisisliil1.b3ta.org
imiill11lnot.afraid.org
user1l1l.a-p-e.m-a-f-i-a.com
l.1ove.you.oil1y.afraid.org
il1l.d0.hear.a1l.mooo.com
hplph0pfiipf10p.afraid.org
1l2li.0n.my.ignorelist.com
ftp.binary01o100li.ygto.com
l1l1il1i.y20o3zuxx.xxuz.com2. The task manager has been covered over, so I can no longer see what processes are running and can't see them to shut them down.
3. I can't access any website or folder with the word Virus in the header.
4. Trying to install an anti virus the screen gets flooded during the installation with the 'are you sure you want to quit setup screen'
Please help,
Cheers,
Chris

I've lost my internet connection on my home computer. I don't even know how to download those removers. I'm kinda posting this from somewhere else.
I'm lost. I can't even acess the internet. When i dial up then it is connected to internet but i can't acess any websites at all.
How do i get rid of a Sasser worm? My computer has been infected with the worm called Sasser. And i wonder how i can get rid of it.

hey Chriswok and Vulture...
If you have taken care of your Sasser Worm problems, please create your own posts outlining your problems in the security and virus forum.
VULTURE: TRY THIS FIRST
if this does not work, come back for more help.
GOOD LUCK!
AOSCLAY

I recommend downloading 'STINGER' it will scan for 41 different current worms and virus's. BE SURE TO READ THE INFO IF YOUR ARE USING WINXP or ME. Check up on 'STINGER' UPDATES OFTEN.
Info if you are running WinXP or ME:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm'STINGER' DOWNLOAD:
http://vil.nai.com/vil/stinger/GOOD LUCK -
LEEP.S. YOU MIGHT ALSO UP YOUR SECURITY AND PRIVACY SETTINGS: RIGHT CLIK MY COMPUTER, THEN CLIK PROPERTIES, THEN THE SECURITY TAB, READ AND RESET THE CONFIGURATION TO MEDIUM HIGH FOR STARTS. ALSO, GET YOUR 'CRITICAL' WINDOWS UPDATES HERE: http://windowsupdate.microsoft.com/
GET A GOOD ANTIVIRUS PROGRAM, AVG FREE EDITION, IF YOU HAVE NOTHING - http://www.grisoft.com/ AND KEEP THE DEFINATIONS UPDATED EVERYDAY - LOTS OF LUCK

i cannot get my computer to reboot, not even in safe mode it goes to a screen that says unable to load hive file. Any suggestions.

I've just cleaned this virus from my system. However, I couldn't edit my registry, start anti-virus programs, and something was constantly trying to connect to the net. The only way to stop the interference was to hit END PROCESS on microsoft.exe in Windows Task Manager. I hope this helps someone in the same boat.

I got the A and B varieties of sasser on Friday night. As far as I know, I've succesfullly removed them using the Symantec and McAffe fix tools (at least the files everybody is talking about are no longer there), but my system still remains painfully slow and there are frequent rebootings...anyone else with the same problem? any suggestions?

I came home the other day to find my computer shutting down on tiself and giving me a one minute times. After a quick research I installed two updates from Microsoft, and the shuting down problem disappeared. Afterwards I ran some scanning apps to check for viruse (including Mcafee, Syamntec and the Sasser detection tool by Microsoft), and all reported my computer to be clean. I also ran a full system scan in safe mode with my updated NAV. So far so good. Sasser disabled my NAV which I manually re-enabled. But after I restart my computer my NAV is disabled, everytime. And I everytime I get the Sasser error message, something about LSAP. Nothing happens besides it, and NAV claims my comptuer to be clean. What can I do to get rid of these after effects? And what can I do to make sure my comptuer is REALLY clean?
Thanks.

heres a problem solver for this new sasser worm crap,if you dont already have it download avg 6.0 free version and update it after you download it,if you have the sasser worm it will kill it.i know because ive had to do it so there you go good luck.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |