Re: Sasser worm

From: Keith W. McCammon (km_at_km.com)
Date: 05/04/04


Date: Tue, 4 May 2004 10:30:41 -0400

See this, which links to a checker, the patch, and the cleaning tool...

http://www.microsoft.com/security/incident/sasser.asp

"Kevin" <kevin.bentley@wdc.com> wrote in message
news:7f2301c43187$62c23fe0$a001280a@phx.gbl...
> We have some machines in our environment that seem to
> have been hit by Sasser this afternoon.
>
> The problem is that I can not find any of the sasser
> components present in the systems? Many of the machines
> scan clear with McAfee Enterprise 7.1.0 and the latest
> Stinger but still get a 60 sec countdown? The countdown
> seems to be resolved by re-installing the 011 patch but I
> am wondering why I cant find any indication of the
> infection? All Viruscan logs are clear?
>
> When I look up the sasser characteristics, I notice that
> the error is slightly different than posted on Mcafee's
> website? We dont get the LSA Shell error and the System
> shutdown error has a status code of 128 instead of
> 1073741819? Any ideas? The slight veriation in behavior
> concerns me?



Relevant Pages

  • Re: Sasser worm
    ... > We have some machines in our environment that seem to ... > have been hit by Sasser this afternoon. ... looks clean I cannot find any sign off the virus exepct for the shut ... The Microsoft patch fixes this issue but I want to know ...
    (microsoft.public.win2000.security)
  • Sasser worm
    ... We have some machines in our environment that seem to ... The problem is that I can not find any of the sasser ... Stinger but still get a 60 sec countdown? ... The slight veriation in behavior ...
    (microsoft.public.win2000.security)
  • Automatically patching machine with hotfix KB824146 using mbsafu.
    ... I didn't want to spend as many hours patching machines with KB824146 exploit ... Mbsafu is an automatic remote patching tool that applies Security updates ... Download and install mbsa. ... Setup a network share with full privileges for the account you will patch ...
    (NT-Bugtraq)
  • Re: [fw-wiz] terminal services
    ... >> pointing out the danger of opening extra holes in your firewall. ... >that a VPN is a hole in the firewall, albeit generally a mitigated hole, ... >people didn't patch their machines. ...
    (Firewall-Wizards)
  • Re: Event ID 6161 for HP 6840
    ... patch related to an exposure via the print spooler service. ... download which offers the option of a local port. ... >> There were no problems with the install and the printer works find so long ... >> 3) All machines on the network can connect to the printer via Internet ...
    (microsoft.public.windowsxp.print_fax)