Re: Not Sasser?!

From: Bruce Chambers (bruce_a_chambers_at_h0tmail.com)
Date: 08/26/04


Date: Wed, 25 Aug 2004 20:22:03 -0600

Greetings --

    You've apparently contracted the latest worm, W32.Sasser.Worm,
specifically designed to attack people who do not update their
computers promptly and who do not practice "safe hex." In other
words, like Blaster, this worm was developed and distributed _after_ a
patch for the vulnerability was announced and made publicly available.
Further, and also like Blaster, this worm could not affect any
computer whose user had taken the basic precaution of using a properly
configured firewall.

    To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next Shutdown countdown begins. This will abort the shut down. Also,
make sure you've enabled a firewall before starting, to preclude any
more intrusions while getting the updates/patches/tools.

What You should Know about the Sasser Worm and its Variants
http://www.microsoft.com/security/incident/sasser.asp

Microsoft Security Bulletin MS04-011
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

W32.Sasser.Worm
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html

A tool is available to remove the Sasser worm variants
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

W32.Sasser.Worm Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

    Oh, and disconnect the computer from the Internet until you can
install current antivirus protection.

Bruce Chambers

-- 
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on 
having both at once. - RAH
"Jessica" <anonymous@discussions.microsoft.com> wrote in message 
news:cb6801c48a4f$9edf99c0$a401280a@phx.gbl...
>I have a virus on my computer that shuts me down and
> restarts    my PC after I get on the internet.  I get the
> same message as the previous posted message by jcb iowa:
> C:\windows\system
> 32/lsass.exe  and the system shuts down and restarts.
> I tried to fix it with the downloads from the windows
> update website---the first one i tried to install said
> there was no infection; the second one i tried to install
> wouldn't even open and said "this application wasn't
> applicable with win32 applications" or something like that.
> so then i went to the symantec web site and installed
> their sasser removal tool, and it scanned my system and
> said that i did not have sasser on my computer.  And i'm
> not rich and can't be paying 50 bucks to speak to a
> symantec virus support person.  So now what??????
> P.S.  I have not had updated virus protection on my pc for
> over a year now, hence the virus.  But I can't get online
> long enough to get buy and download protection!!!!
>
> Thanks,
> Jessica 


Relevant Pages

  • Re: Continued shutdown, move iniciated by NT Authority System
    ... virus can infect you. ... my system turned out clean of this worm. ... >> The first irrecularity happen after installing Norton ... >McAfee AVert Stinger Virus Removal Tool ...
    (microsoft.public.win2000.setup)
  • Re: Problems with lsass.exe
    ... i am also having the lsass & random reboot problem. ... install some other components of xp. ... > You've apparently contracted the latest worm, W32.Sasser.Worm, ... > McAfee AVert Stinger Virus Removal Tool ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: NT Authorization (60 second shut down)
    ... It's definately Win32.MSBlaster virus, Because I suffered from similar problem. ... > sure you've enabled a firewall before starting, ... > What You Should Know About the Blaster Worm ... > W32.Blaster.Worm Removal Tool ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Isass.exe Help Needed !!!
    ... Further, and also like Blaster, this worm could not affect any ... McAfee AVert Stinger Virus Removal Tool ...
    (microsoft.public.windowsxp.security_admin)
  • Re: XP - cant load anti-virus software
    ... The system is already infected by a virus or worm that is preventing the ... NortonAntiVirus folks to tell you it is an operating system issue is exactly ... and then successfuly install an antivirus program. ...
    (microsoft.public.security.virus)