Main Restorations Software Audio/Jukebox/MP3 Everything Else Buy/Sell/Trade
Project Announcements Monitor/Video GroovyMAME Merit/JVL Touchscreen Meet Up Retail Vendors
Driving & Racing Woodworking Software Support Forums Consoles Project Arcade Reviews
Automated Projects Artwork Frontend Support Forums Pinball Forum Discussion Old Boards
Raspberry Pi & Dev Board controls.dat Linux Miscellaneous Arcade Wiki Discussion Old Archives
Lightguns Arcade1Up Try the site in https mode Site News

Unread posts | New Replies | Recent posts | Rules | Chatroom | Wiki | File Repository | RSS | Submit news

  

Author Topic: Sasser worm  (Read 1346 times)

0 Members and 1 Guest are viewing this topic.

NoBonus

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 688
  • Last login:January 07, 2007, 06:48:58 pm
  • "Now that's a fine example of California's Gold"
Sasser worm
« on: May 04, 2004, 11:05:09 am »
So, I have seen the Sasser worm infect two computers so far (not mine, people who needed my help fixing it).  Has anyone else seen or gotten the Sasser worm?  I found that the 60 seconds Sasser gives you before rebooting is just enough time to download Symantic's Sasser removal tool, but not enough time to really search for the tool and read any instructions, so it took a couple re-boots before I got it downloaded. (It was kind of like a fun game, download the anti-virus before your system reboots)

NoBonus

abrannan

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 858
  • Last login:July 25, 2012, 11:32:14 am
  • Building a cabinet in perpetuity since 2002
Re:Sasser worm
« Reply #1 on: May 04, 2004, 05:06:28 pm »
Sasser (and it's three variants) and the latest version of GaoBot have been my life the past few days.  But this outbreak is nothing compared to the biggies of the past couple of years.  Nimda and SQLSlammer were the biggies, with Blaster close behind.

You can just kill the avserve2.exe process and delete the %windir%/avserve2.exe file in the 60 seconds to reboot.  That will stop the worm from restering on reboot.  Then you can get the tool and cleanup.

Let me just take this opportunity to make a Public Service Announcement:

Everyone, please run a firewall on your high speed connections!  There are plenty of free personal firewall programs out there, if you don't have a hardware firewall.  Also, please patch your systems!  Microsoft has provided the automatic update client to automatically check for and install patches on 2000 and XP.  Also, please get an anti-virus program and run it.  If it isn't already, configure it to automatically check for updates as well.  If everyone did these three things, viruses like Sasser wouldn't create half the impact they do today.



Ah, there, now I feel better.
If no one feeds the trolls, we're just going to keep eating your goats.

Tailgunner

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1156
  • Last login:October 06, 2009, 01:21:16 pm
  • ...
Re:Sasser worm
« Reply #2 on: May 04, 2004, 06:31:18 pm »
My mom's system caught at least two variants of Sasser this past weekend. Annoying little bugger.

Edgedamage

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1261
  • Last login:October 06, 2018, 12:21:23 am
Re:Sasser worm
« Reply #3 on: May 04, 2004, 06:44:25 pm »
Yah some GOOF!!!!!!!!!!! in our office opened a email from someone they didn't know and unleashed the worm. The only system that didn't get hit was my work station. Call me anal but I check the microsoft update site each day when I log in. Also I do a live update on my systems virus scanner each morning. Man I wish I had the IT guys job here he just smokes butts all day long while each system has the little update globe beside the clock in the system tray.
Curls in the squat rack !?!?!

shmokes

  • Just think of all the suffering in this world that could have been avoided had I just been a little better informed. :)
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 10397
  • Last login:September 24, 2016, 06:50:42 pm
  • Don't tread on me.
    • Jake Moses
Re:Sasser worm
« Reply #4 on: May 04, 2004, 08:42:54 pm »
Why don't you just tell windows to apply critical updates automatically at a certain time every day?  Then you don't have to check their website.
Check out my website for in-depth reviews of children's books, games, and educational apps for the iPad:

Best Kid iPad Apps

Valence

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 151
  • Last login:June 15, 2004, 10:44:49 pm
  • I want my own arcade controls!
Re:Sasser worm
« Reply #5 on: May 04, 2004, 09:02:07 pm »
I found this worm to be mild. Fairly easy to remove and itself was very buggy. I support about a thousand users and we had 7 infections. The one where it causes a reboot does not actually infect anyone. (Infect as being able to reproduce) We had about 18 of the RPC errors. Also, if you logged into the machine with a different user profile it didn't crash.

Edgedamage: These virui are not transmitted by emails. They use an open port as far as I know.  :)


NoBonus

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 688
  • Last login:January 07, 2007, 06:48:58 pm
  • "Now that's a fine example of California's Gold"
Re:Sasser worm
« Reply #6 on: May 05, 2004, 12:42:03 am »
He may be referring to the Netsky variant that used "Sasser worm removal tool" as bait.

knuttz

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 136
  • Last login:January 08, 2025, 05:36:02 pm
  • ..................................................
Re:Sasser worm
« Reply #7 on: May 05, 2004, 01:36:58 am »
I kinda like viruses, worms and the like.  They are a nice change of pace from the normal daily routine.

jk
"Look at all those hamburgers. You can't eat all those hamburgers you stupid fella, OH GEEZ!" "OH he's gonna do it! He's so rediculous."

Apollo

  • Yes You Can Have A Custom Title
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1877
  • Last login:May 27, 2021, 10:49:02 pm
    • Eight Bells
Re:Sasser worm
« Reply #8 on: May 05, 2004, 01:43:09 am »
I agree, I actually get kind of a thrill when I get a virus. If you have the right protection ( gotta be Norton ) and you know the basics it's pretty cool. It's like yeah yeah you can't get me ( that's not an invitation by the way, lol ).

knuttz

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 136
  • Last login:January 08, 2025, 05:36:02 pm
  • ..................................................
Re:Sasser worm
« Reply #9 on: May 05, 2004, 04:47:45 am »
Yeah, my brother got a virus that was able to close his browser if he typed in the word virus, antivirus, etc into the search window.  It would also attemt to cancel Norton AV's instilation program if it was ran.  It was horrible and beautiful at the same time.
"Look at all those hamburgers. You can't eat all those hamburgers you stupid fella, OH GEEZ!" "OH he's gonna do it! He's so rediculous."

patrickl

  • I cannot know for certain which will be tastiest
  • Trade Count: (+2)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 4614
  • Last login:August 27, 2021, 09:25:30 am
  • Yo momma llama
    • PocketGalaga
Re:Sasser worm
« Reply #10 on: May 05, 2004, 06:38:03 pm »
I used to collect virii (virusses?) when I during my study days. The University PC's would always have loads of them on their hard disks. 8)

This signature is intentionally left blank

fredster

  • Grand Prophet of Arcadeology
  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 2267
  • Last login:February 16, 2019, 04:28:53 pm
  • It's all good!
Re:Sasser worm
« Reply #11 on: May 06, 2004, 12:53:44 pm »
The microsoft site has a thing to do to stop the virus so it won't knock you offline.  You have to make a logfile.

Some of you guys LIKE viruses?  I think they should bury the guy who unleases one of the these things in a hole with his feet sticking out.

If you are computer savy, fine.  But I fixed one yesterday where the woman was litterally in tears about it.  I don't think it's funny or cool at all.
King of the Flying Monkeys from the Dark Side

knuttz

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 136
  • Last login:January 08, 2025, 05:36:02 pm
  • ..................................................
Re:Sasser worm
« Reply #12 on: May 06, 2004, 02:05:07 pm »
fredster, No I don't really like viruses.  I was just joking around.
"Look at all those hamburgers. You can't eat all those hamburgers you stupid fella, OH GEEZ!" "OH he's gonna do it! He's so rediculous."