Sasser Worm virus

49 public posts in this discussion.

Post 1

make sure you update ya windows.. just got this today.. and had a lot of trouble with it at work!!

http://www.microsoft.com/security/incident/sasser.asp

Post 2

a lot of trouble?

I HATE THAT FUCKING VIRUS.

Post 3

I don't run any form of firewall. I don't run any form of anti-virus protection.

I've had ONE virus in the past two years.

I don't know how you guys do it.

Post 4

hahahaha my school already is infected :D

Post 5

no computer virus not sex ones jamie :P

Post 6

Quote from rec:
I don't run any form of firewall. I don't run any form of anti-virus protection.

I've had ONE virus in the past two years.

I don't know how you guys do it.

How much do you download?
I turned my computer on for about 4 hours this afternoon, WITH Norton antivirus, which was up to date.

I am now trying to remove this virus via safe-mode.

Viruses give me the fucking shits.

Post 7

Actually, I've got a good idea of how you might do it... if you insist on running Outlook and/or Internet Explorer for starter - both of which are huge security holes for any system.

Post 8

except its a worm not a virus.

Post 9

And a worm is basically a virus that has been told to spread.

Worms however generally set themselves up in active memory, rather than attach themselves to a file. It still replicates like a virus, but doesn't replicate locally to other files, rather relicates itself over networks.

It's all Malware, who cares exactly what it is. It's a bastard, that's what it is.

Post 10

Meh rec, i run a firewall and it blocks intrusion attemtps, the sub seven trojan and backdoor trojans consantly, i dont know how you do it... Are u running a modem with hardware firewall?? As i dont seem it likely that u have NO firewall... Are you running windows firewall?

Although i do say ive never had a virus, or worm in my computer

BTW.. lol at windows update!! Im downloading the update at 2.7K/s and ive got 1.5mbit...

EDIT Oh, that was with getright.... wothout it i d/l normally. My bad
Thanx Matt

Post 11

I'm not running windows firewall, my modem is simply that and does not boast firewall or router functions.

I have no protection, yet don't get slapped.

I run Mozilla, and Mozilla mail. I try not to make my primary e-mail addresses public, but never open an e-mail if I do not recognise the sender, I definately do not try to open any attachments if I can't identify it as something I want, even if it's from someone I know. I block ALL popups and do not have java enabled, nor do I auto-accept cookies.

I'm simply careful.

Post 12

My day was awsome. I actually had fun

Post 13

Quote from rec:
I'm not running windows firewall, my modem is simply that and does not boast firewall or router functions.

I have no protection, yet don't get slapped.

I run Mozilla, and Mozilla mail. I try not to make my primary e-mail addresses public, but never open an e-mail if I do not recognise the sender, I definately do not try to open any attachments if I can't identify it as something I want, even if it's from someone I know. I block ALL popups and do not have java enabled, nor do I auto-accept cookies.

I'm simply careful.

You might not have a firewall, but your isp might. I know of a few that are running firewalls, altough they can be a pain in the ass. Also if you have an ip that is not near many others. Or you could just be really lucky.

I havent seen this virus yet tho, anyone know if it attacks win2k3 servers?
I cant be bothered looking around for answers to that question :P

Post 14

ok im in a predicament.... it has taken away the turn off button disabled the tab for system restore tried to turn off the comp... and the symnatec remover doesnt work!!!!!! wtf do i do its driving me round the bend!!!!

EDIT - it also doesnt like to let me on the net gives me all sorts of errors and also doesnt change in safe mode... i can access things in safe mode but it still doesnt find nething my last hope was a format but its not my comp so i dont want him to loose nething........

Post 15

I run a firewall AND a fucking Virus scanner.

Enough with the smug shit.

I know of other people who also use alternative browsers and mail applications who also are infected with the virus in question.

Its not a matter of careful, its a matter of lucky.

Post 16

ok now help me.... it also says something like
LSA shell (export version) has encountered a problem and needs to close

Post 17

look for a process called avserve.exe.

stop that service to take your machine back

The worm remover works fine when it is downloaded and run.

When you have gotten rid of the worm, install Norton Internet Security on your sys if you havent already to get it upto date.

This worked for cocky and myself.

Also it will only happen to the computer that is connected to the internet not any of the others as its ports are stealthed due to not having a physical presence on the net.

Goodluck to all those that have it.

Down with the Sasser Worm :P

Post 18

Well I've been lucky for two years... woo. ;)

Post 19

ahhh ffs the only thing that even remotely loooks suspiscious is SysAI.exe thats why its giving me the shits because its not like the other ones out there.... otherwise the symnatec remover wouldhave discovered it... but it still says that it cant find nething and then when the error message comes up i cant run it nemore and thats when the funny shit starts happening it also changed what my comp is in the system it is now a x86 family 6 model 8 stepping 10 WTF!!!! and has changer all the processes to unknown in the username comlunm

Post 20

i dont have any antivirus software/firewall and i havent managed to get any viruses and i use IE and OE, i have a few evils but spybot and sum other program i got keep them at bay

Post 21

It got thru my firewall dont think i specifically nailed wich port thru wich it came but it got picked up and deleted at work by Norton System Protect and at home by NOD32 and removed

Not super bad as far as virus go.

Yes spelling is bad

Post 22

ok well still hasnt been fixed there might be a new version and i think i have it god this sux

help me god dammit

Post 23

Quote from K_I_Z_A:

help me god dammit

no ..

And not to be a smart arse, you demanding shit gets you nothing. You asking gets you answers. And you son have blown your chances. The the bin for you.

Post 24

Quote from RaKeR:
Also it will only happen to the computer that is connected to the internet not any of the others as its ports are stealthed due to not having a physical presence on the net.

Haha, go me connecting through a Router :) I don't get many viruses or anything. Outlook Express does the job fine, doesn't open e-mails just previews them.

rec, you're just not cool 8) or important enough to be attacked :P worms are scared you will have your way with them :wink:

Post 25

Another thing to mention, which OD reminded me of, is that on top of my caution, I frequent WindowsUpdate.com - always keeping my XP install up to scratch.

Post 26

like rec, i don't run any firewalls or virus protectors.

in the last 2-3 years, i've only had one virus, and that was the blaster one.

why am i not scared? i don't frequent sites that put me at risk. i only read emails from those i know, and i rarely get emailed/use email anyways. the email i mainly use is my ANU one. and now that i use mozilla, i'm not AS concerned.

saying that though, i bet i just jinxed myself

Post 27

Quick, knock on wood!

Post 28

I'm not a network expert, but my understanding was that sitting behind a DSL modem using NAT makes your machine essentially unaddressable from the internet.

Which would imply that viruses cannot find your machine, and thus infect it. If this is true, it explains why I also manage to remain relatively virus free simply by keeping my windows patches up to date.

Oh, and typing "esync; emerge -uv world" sometimes. Although I'm thinking that on my next go around the linux roundabout I might go back to Debian. Gentoo is fast but about as stable as OverDrive.

Post 29

You not knowing what your doing has no bearing on this obviously.... geez I must've gotten to him - either that or he fancies me...

Post 30

*knocks on wood*

i genuinely thank both El Pres and OD, u've both made my night, i'm in stitches.

Post 31

Quote from Amphibious One:
I don't get many viruses or anything. Outlook Express does the job fine, doesn't open e-mails just previews them.

previewing them IS opening them. simply not in a separated view.

Post 32

The Telstra prodivded Alcatel Speedtouch Home external isn't a full NAT router, neither are most basic DSL modems. The Alcatel Speedtouch Pro is, however.

Post 33

Like rec and cow I don’t run virus software.
Why be so stupid? You may ask.
Well its simple I think they are way overrated and a waste of money. I’m always clean of viruses and I do a scan whenever I am bored (usually about once ever 8-10 weeks) using Trend Micro System Cleaner. I also do a scan with ad aware every now and again.

My opinion on stopping them is to install service pack 1 ASAP (assuming your using winxp) and to check the security patches at the windows website every month or so. Also as others said don’t open stupid e-mails with attachments that aren’t gif, jpg, txt, and so on.
Never open bat, exe, zip, rar
If you want to send/receive them use msn :P

I think its all pretty common sense really and I don’t know why other people using virus programs get so much shit. It kinda frustrates me to think about it really.

PS: I may get no virus/worm troubles cause my dads computer is the gateway but I’m not sure *shrugs*
That’s enough typing.

Post 34

thats certainly why you wouldn't get any worm troubles; virus scanners provide a somewhat false sense of security for people however, by having them, people think they are safe, and do not need to take other measures to ensure their continued clean operation. meh

Post 35

geez ok i wasnt demanding information that as just me venting my frustration at the bloody genius/idiot who made this virus.... dont get so defensive. i didnt bloody mean it

Post 36

I don't get viruses unless someone on my network specifically installs a program which obviously has a virus on it.

When that happens I am so glad that I have antivirus software.

Symantec Corporate AV is a very nice little program ;)

IMO everyone should have either some sort of firewall or regularly service their computer with a free virus scan like AVG (download, scan, uninstall).

Post 37

Yeah i dont have any firewall for my system, but i do have norton AV, which is very handy for screaming 20 windows saying:
you have a virus!
Get rid of it Cancel

Failed to get rid of virus!
Retry Cancel

so on so on. (something like that)

Im good with my computer, i dont get virus'.

But my fucking computer illiterate family insist on it.

Post 38

Well, after booting into safe mode, patching up windows and removing the virus, im hopefully all clear.

....until the next one comes along....

El Pres - Im also sitting behind a router with NAT.

Post 39

Did anyone else just notice Knight's perfect grammar and spelling?! :O

This virus is SO yesterday.

Post 40

13000 infection attempts since i started logging (about midnight). woot.

Post 41

Havent had a major virus downtime for the past 7 years. No joke, honest and I'm not shitting you either. I did have an intrusion in the form of a trojan horse while I was in Octa4 that I kept at bay for 8 months using a firewall. It desperately tried to get past my firewall but to no success... it was like an animal coraled in my miniature defenses. Toyed with it for some time trying to know where the author was.

I do a combination of best practices and behaviors to keep those malicious code from getting me. I can attest that OD can claim my IP in Octa4 does not exist so I become impoverish to any of thier attempts of infection.

Post 42

i sit comfortably behind a hardware firewall so i dont need to be concerned but have helped many people with it, it is just a way of life and thats that!

some of my computers here are barebone installs with no protection but like i said i do not exist on the internet :)

dazza am stealth

Post 43

No anti-virus, you could connect my machine directly into a virus laden network and I'd be uninfected.

Nothing violates the Ironclad :twisted:

I'd offer points for guessing how I do it, but I suspect too many of you know already ;).

Post 44

yeah, you sacrifice gaming ability.

Post 45

:)

Post 47

When you're already really, really bad... there's not a lot to sacrafice. *grin

Post 48

lol bloody linux users

Post 49

2 Bloody days running around after this damn virus.

GAH@!!!!