PSA: Sasser (Running Win XP? Please read!)

Saaby

Flashaholic
Joined
Jun 17, 2002
Messages
7,447
Location
Utah
Hi everybody,

I spent probably 4 hours out of my 6 hour shift tonight (at least) working on Sasser worm problems. Thus I feel it necessary to take it upon myself to make a PSA, if you will, about sasser. What it is, what can be done to prevent it, and what to do if you already have it.

First of all let me climb up on my soap box and say that if you do end up calling in for tech support please be nice to the tech support agent. At my call center we were never less than 30 in queue (That means 30 people on hold waiting for an agent) and most the night we were between 200-300 waiting for an agent. You may be stressed, but the agent is stressed too. Realize the pressure is on to fix people's problems (so they don't have to call back) while keeping them happy (so they don't cancel their service) and, oh yeah, could you hurry it up--there are 300 other people waiting in line for advice.

Off the soapbox, onto the advice.

What SASSER is, and how does it relate to BLASTER?
Sasser is a worm similar to BLASTER. BLASTER popped up a box that shut your computer down via a hold in the Remote Call Procedure. SASSER does it through the LOCAL SECURITY AUTHORITY. If your computer is getting shutdown upon connection to online by a long, rectangular box that is from "Remote Call Procedure" that's Blaster. "Local Security Authority" is SASSER.

How do I prevent it?
Windows Updates. Buck it up and do them. Even on dialup. It's going to save you time in the long run. check back every couple of weeks and stay up to date on your patches. Will it prevent all virusses? No, but patches were released to prevent BLASTER and SASSER before the virusses were in the wild.

But I already have it? What now?
SASSER can be removed in 3 easy steps
1. Turn on a firewall. In Windows XP this is fairly simple (You're all using Windows XP right?)
--Start:Control Panel
--Switch to Classic View (On the left).
--Network Connections
--Look for icon for LAN or "MSN" or "AOL" "EARTHLINK" "JUNO" or whatever. Right click on the icon and say "Properties"
--Click the "Advanced" tab
--Put a check in "Protect my computer"
--Click OK.
--Close control panel

2. Stop the blaster process
--Ctrl+Alt+Delete. This should bring up the task manager. Click "processes" and then click the "Image Name" header twice to sort the processes A to Z
--End the processes "avserve.exe" and/or "avserve2.exe" as well as any processes that are 4 to 5 numbers followed by "_up.exe" as in "7623_up.exe"
--Close task manager

3. Get online using the firewalled connection. Hopefully SASSER doesn't shut you down. If SASSER pops up pull up your system time (Double click on the time in the corner) and set the date back 1 day. This will give you 24 extra hours to do what you need to do. Setting back the date/time is only effective after SASSER has popped up to shut you down.

4. Run all your windows updates. Buck up and do it. Keep up to date on them from now on.

5. Run the SASSER removal tool

That should fix you up! Any questions?
 

14C

Enlightened
Joined
Mar 9, 2004
Messages
844
Location
Reno, Nevada
Got to point out the firewall that comes with XP checks for incomming stuff and not for outgoing stuff so if you got a horse you might not know it. STILL it should be ON.

Check out Zone Alarm - www.zonelabs.com - they have an excellent free version that will monitor incomming and outgoing connection attempts.

DO the windows updates.

The sasser removal tool will work right off of the MS WWW site.
 

Saaby

Flashaholic
Joined
Jun 17, 2002
Messages
7,447
Location
Utah
But it's pointless to run the tool without first running your windows updates as you still have more than a small chance of SASSER simply getting in again.
 

PaulW

Flashlight Enthusiast
Joined
Mar 23, 2003
Messages
2,060
Location
Laurel, Maryland
Saaby,

No trouble here this time around, although I had worms a few months ago. I appreciate the kind of information you have posted here. It's gonna be very helpful to those who have been infected. I think it would be wise for those who have not yet downloaded the patches to keep a copy of your first post until they have the patches installed.

Thanks,

Paul
 

kongfuchicken

Flashlight Enthusiast
Joined
Dec 21, 2003
Messages
1,570
Location
Santa Cruz, CA
One thing: if you guys aren't running xp but 2000, Ms has released a patch that's bugged. If you use windows update with win 2000 to get rid of sasser, you might not be able to login again...
Quite a few people in my dormitory were affected and are now running xp instead. The win xp patch on the other hand, works like a charm... well considering it's from Ms...
 

Saaby

Flashaholic
Joined
Jun 17, 2002
Messages
7,447
Location
Utah
**UPDATE
In XP the firewall should cover you--which is good because if you set the date back too far Windows Update won't work /ubbthreads/images/graemlins/blush.gif
 

Chris M.

Flashlight Enthusiast
Joined
Jan 17, 2001
Messages
2,564
Location
South Wales, UK
In related news, it was reported today that the creator of this worm has now been caught. An eighteen year old German man was arrested at his mom and dad`s home today (or yesterday) and has apparently confessed to creating the worm.

Here in the UK, the national Coastguard`s computer system was badly affected, although it was quickly restored within a day. Worldwide, computer systems were affected causing massive disruption including the German railway services. Of course, it is still active, though most important systems are hopefully now patched and protected. If anyones life was in any way put at risk as a result of this worm`s activities, I hope this kid gets charged with attempted murder. Whatever happens, I hope he is jailled for a long time and banned from owning or using any computer equipment for the rest of his life. Same goes for anyone who creates a virus or worm that puts people at risk.

At least they got the son of a *****. But it`s only a matter of time before it happens all over again....

/ubbthreads/images/graemlins/mad.gif
 

DavidH

Newly Enlightened
Joined
Sep 13, 2001
Messages
128
Location
Southern California
Our office did pretty good. We already had the proper MS patches in place and our AntiVirus servers check for new signatures every hour. Symantec released teh update on the weekend. By the time our over 8500 customers got to work, the definitions that prevent it from spreading were already on everyone's workstations and servers. I didn't have to worry about it affecting the Mac systems at home and work.
 

NeonLights

Flashlight Enthusiast
Joined
Jan 18, 2003
Messages
1,493
Location
Ohio
Sasser was running rampant on my home PC for a couple of days, I finally figured out what it was, killed it, and activated a firewall from McAfee that had been on my 6 month old PC but never turned on. No problems at all in a week since.

-Keith
 

The_LED_Museum

*Retired*
Joined
Aug 12, 2000
Messages
19,414
Location
Federal Way WA. USA
My stepmother in California says her computer at work shuts itself down unexpectedly. It runs XP.
I'll pass the information along to her tomorrow when she's at the computer. /ubbthreads/images/graemlins/smile.gif
 

DavidH

Newly Enlightened
Joined
Sep 13, 2001
Messages
128
Location
Southern California
[ QUOTE ]
The_LED_Museum said:
My stepmother in California says her computer at work shuts itself down unexpectedly. It runs XP.
I'll pass the information along to her tomorrow when she's at the computer. /ubbthreads/images/graemlins/smile.gif

[/ QUOTE ]

Hmm... I think that's what Blaster does to your system.
 

sotto

Flashlight Enthusiast
Joined
Jan 30, 2002
Messages
1,062
Location
Old Bay City, CA
About every other time or so that I boot up my HP Notebook, I get a window that pops up on my screen that says I have the Sasser wurm and says to click on it. I just click "cancel" or close the window. I have my XP firewall up and have run the anti-sasser software patch from Microsoft which repeatedly says no Sasser wurm is detected. How do I get rid of this stupid warning?

Thanks.
 

Latest posts

Top