Re: Sasser like symptoms

anonymous_at_discussions.microsoft.com
Date: 07/29/04


Date: Thu, 29 Jul 2004 12:48:08 -0700

Stinger got it! Thanks!

For the record (should this help others) it was the
W32/Sdbot.worm.gen.h virus
stinger detected and deleted file WINNT\system32\ntce.exe

promise will go hunt down firewall before taking that
machine back online. Thanks for the help.

>-----Original Message-----
>1) Get a firewall in place ASAP - don't connect to the
Internet without it,
>even for a second
>2) Try running the McAfee Stinger tool (available for
download from their
>website).
>
>
>Gill wrote:
>> i have sasser like symptoms on my home Win2000 pc but am
>> uncertain i have correctly diagnosed the exact culprit.
I
>> do get the winnt/system32/lsass.exe 128 error and auto
>> rebooting but have none of the related avserve files or
>> processes running?
>> Is this sasser or something else related. having spent
>> hours running Norton, spybot and the blasterworm removal
>> tool to no avail before trekking out to an internet cafe
>> to google for an answer i'm loathe to keep running round
>> this hamster wheel without making sure i'm now about to
>> treat the right thing. Can anyone advise?
>
>
>.
>



Relevant Pages

  • Re: Norton removal
    ... your computer is infected by more than just Sasser. ... clean machine download Stinger ... I have adaware and spybot on my ... I was finally able to uninstall Norton Internet ...
    (microsoft.public.security.virus)
  • Re: LSASS.exe
    ... Trend Micro free online scan and have come up with nothing.No Sasser. ... ran the Symantec's removal tool and still nothing. ... > What You should Know about the Sasser Worm and its Variants ... > McAfee AVert Stinger Virus Removal Tool ...
    (microsoft.public.security.virus)
  • Re: sasser worm
    ... Get STINGER, it has been updated to remove Sasser and 40 ... Lsass reboot meesages and | reboots but none of the files associated with Sasser.A, B. C. or D. Seems | to be a new variant. ... |> I have nav 2004, and auto protect as well as live update keep getting |> disabled with no way for me to reenable it and the symantec sasser removal tool does not detect sasser. ...
    (microsoft.public.security.virus)