News Sasser worm 'spreading rapidly'

Discussion in 'Article Discussion' started by GreatOldOne, 3 May 2004.

  1. GreatOldOne

    GreatOldOne Wannabe Martian

    Joined:
    29 Jan 2002
    Posts:
    12,092
    Likes Received:
    112
    This from the Beeb:

    A new internet virus spreading rapidly around the world may already have infected millions of computers.

    Sasser, unlike a virus which travels through e-mails and attachments, spreads directly from the internet.

    It attacks recent versions of Microsoft's Windows causing the computer to shut down.

    The worm exploits a security flaw, but this can be prevented with a Microsoft patch.

    It typically shuts down the computer then automatically re-boots it and repeats this process several times, but is not thought to cause lasting damage.


    More here

    Ah, another day, another worm. :rolleyes:
     
  2. [cibyr]

    [cibyr] Sometimes posts here

    Joined:
    30 Nov 2003
    Posts:
    749
    Likes Received:
    1
    Sounds like blaster all over again. I think one of my friends got it, before there was any AV for it. Lucky I'm behind a NAT :D
     
  3. BioSniper

    BioSniper Minimodder

    Joined:
    5 Feb 2002
    Posts:
    3,815
    Likes Received:
    18
    ditto :thumb:
     
  4. KryoNexus

    KryoNexus What's a Dremel?

    Joined:
    21 Jan 2004
    Posts:
    122
    Likes Received:
    0
    yeh, sounds exactly like blaster. can't fault the maker for being original i guess ;-)
     
  5. Guest-16

    Guest-16 Guest

    when will people learn NOT TO OPEN DAMN EMAIL ATTACHMENTS! :rolleyes: :duh:
     
  6. dyzophoria

    dyzophoria Minimodder

    Joined:
    3 May 2004
    Posts:
    393
    Likes Received:
    1
    i read it doesnt spread via email/attachments, it spreads by attacking a randomly selected ip address. :eeek:
     
  7. -:: M@ ::-

    -:: M@ ::- Testify!

    Joined:
    3 Oct 2003
    Posts:
    1,062
    Likes Received:
    0
    any chance this will cause an error in lsass and then tell me the computers gonna shutdown in 1 mintue and countdown, as since yesterday I have that :)
    and assumed it was just summat to do with my new pet the wininit32.exe worm, not 2 viruses in a week :(
    arrrrrgggggghhh

    *ahem*

    - M@

    ::edit::
    oh and yeah, i have had no email attachments, im not that stupid, so it has 2 be the random ip thingy
    grr
     
  8. Manitowic999

    Manitowic999 What's a Dremel?

    Joined:
    17 Mar 2004
    Posts:
    96
    Likes Received:
    0
    Removed it from a friends computer last night. Hooks into LSASS.EXE. It's the service that controls windows logins. Once it gets in, the worm simply runs Shutdown.exe with system permissions (ie:no cancel) with a one minute timer. Makes thinks interesting, took me about three times to finally get it. :D Not very distructive, only creates a server on your computer, probably a DDOS worm. Easy to remove.

    Pawn_King110: Start in safe mode, run your virus scanner. I was able to remove it with a Trend Micro online scan. It will leave junk though, so if you have Norton or another, use it. it leave non-repairable files in your "C:\windows\system32\" folder. Just quarentine them and then delete them. Good Luck. :thumb:
     
  9. neonplanet40

    neonplanet40 What's a Dremel?

    Joined:
    3 Mar 2003
    Posts:
    479
    Likes Received:
    1
    Ive got somthin called lsass.exe | SYSTEM | OO | 1,312

    But i have had no probs with computer trying to shut down etc....

    PyRo :wallbash:
     
  10. Manitowic999

    Manitowic999 What's a Dremel?

    Joined:
    17 Mar 2004
    Posts:
    96
    Likes Received:
    0
    LSASS.EXE is a critical windows service. It's not the problem. The worm just causes a problem in it.
     
  11. DeadTeddy

    DeadTeddy What's a Dremel?

    Joined:
    22 Apr 2004
    Posts:
    71
    Likes Received:
    0
  12. VadimtheConqueror

    VadimtheConqueror I love the little tacos...

    Joined:
    10 Jul 2002
    Posts:
    1,333
    Likes Received:
    0
    removal tools take a long time.

    boot to safe mode
    delete avserve.exe or avserve2.exe, and *_up.exe, then go into your regitry, and do find for avserve or avserve2, depending on which variant you have. i have a feeling luxafyj is a third variant, would like confirmation on that tho.
    after the reg keys are gone, go and turn on windows firewall on your net connection or another firewall program, or a router with builtin firewall.
    reboot to normal mode
    run windows update
    done

    i've only done the fix once. everyone else in the office has done it about 20 times now, people keep keep keep calling about it, it'sj ust easy enough that they dont need to call me.
     
  13. Piratetaco

    Piratetaco is always right

    Joined:
    15 Apr 2004
    Posts:
    2,746
    Likes Received:
    1
    whats a NAT?
     
  14. RTT

    RTT #parp

    Joined:
    12 Mar 2001
    Posts:
    14,120
    Likes Received:
    74
    Network Address Translation - basically a device that makes a network of computers appear as just one to the rest of the internet.

    If you're firewalled (or non windows :D) you'll escape this Sasser thingy.
     
  15. Lazy

    Lazy Meow?

    Joined:
    13 Nov 2001
    Posts:
    4,481
    Likes Received:
    1
    when will people learn TO READ ABOUT THE VIRUS! :rolleyes:


    :D
     
  16. -:: M@ ::-

    -:: M@ ::- Testify!

    Joined:
    3 Oct 2003
    Posts:
    1,062
    Likes Received:
    0
    Cheers Manitowic999 :D Unfortunatly im a lazy **** so got the removal tool instead, but thanks for that anyways!!
    Woot, no random shut downs :)

    - M@
     
  17. Pygo

    Pygo Rick Relixed

    Joined:
    26 Jan 2003
    Posts:
    2,179
    Likes Received:
    8
    hehe, I got that virus two nights ago. Had it off within the half hour of not even knowing what it was. I got the shutdown message about 5 mins after going online with dialup. So, I went into safe mode, and then ran msconfig. Found avserve2.exe and thought hmmm... nothing to do with avg, and I haven't seen it there before. unchecked it. Rebooted into normal mode. ran a virus scan. found and deleted. then went directry to windows update after enabling the winxp firewall. no probs since. :thumb:
    Although, I have had like 5 people call me at work about this shutdown thing and what not. Got like 4+ computers comming in today/tomorrow already. I guess this means I have to work for my hard earned money :duh: :lol:
     
  18. -:: M@ ::-

    -:: M@ ::- Testify!

    Joined:
    3 Oct 2003
    Posts:
    1,062
    Likes Received:
    0
    ok
    so i had the process adserve.exe running, which i deleted a couple of nights bk on my weekly wtf is running in processes clean..
    now it still shuts my machine down, but theres no registry key where there should be :S
    and my machine keeps running down, so either i have summat else, or theres sommat screwed on my computer in the lsass thing, but thats what the virus attacks, and i did have the .exe on the computer....crap...

    erm, :waah: help??

    pwease?
    - M@
     
  19. Pygo

    Pygo Rick Relixed

    Joined:
    26 Jan 2003
    Posts:
    2,179
    Likes Received:
    8
    OK. do you have a virus scanner? If so, is it up to date?
    Also, if you are on the net, you will most likely get the virus. If you go to windows update, you can download a patch for the virus I beleive.
    run a full virus scan.
    Or, if you want, you can go into safe mode, and use the McAfee Stinger tool to remove it.
    http://vil.nai.com/vil/stinger/
    ^^^ linky for stinger.

    Also, if you want a good free virus scanner, goto www.grisoft.com and click on the AVG free edition link, and enter the info there.
    I think that is it, anything else I forget?
     
    ajack likes this.
  20. -:: M@ ::-

    -:: M@ ::- Testify!

    Joined:
    3 Oct 2003
    Posts:
    1,062
    Likes Received:
    0
    ok, well did all that found nothing
    then 10 mins later, lsass got its 'problem' and shutdown
    just like the virus does, so its here somewhere, or a diff varient???
    but this is taking the piss now :waah:
    grrrrr

    - m@
     
Tags: Add Tags

Share This Page