Internet Access by Area Code
Internet Service by City/State
 FAQFAQ   SearchSearch     RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in  ISP Guide    

Sasser.A Sasser.B Sasser. C & D



 
Top Rated Dialup Internet Service Providers & Top Rate DSL Provider
Post new topic   Reply to topic    ISP Guide -> ISP Guide Forum Index -> Internet Utilities & Software  
Get Instant quotes for
Home: DSL Cable Satellite
Business: DSL T1 VoIP


Latest Discussions 
   Adobe Photoshop CS4 Ultra Light Edition
   what is lucoms~1.exe process ? Is lucoms ...
   Download McAfee Total Protection 2009
   Wireless Internet
   isass.exe makes computer restarts
Popular Discussions 
  what is lucoms~1.exe process ? Is lucoms ...
  Windows XP- lsass.exe 60second System Sh ...
  what is dumprep.exe process ? Is dumprep ...
  Windows XP/2000/ME : lsass.exe error
  lsass.exe removal
Hottest Discussions 
   Windows XP- lsass.exe 60second System Sh ...
   Netscape Internet Keywords
   what is lucoms~1.exe process ? Is lucoms ...
   Dialup connection problems
   Links not responding, IE 6 freezes when ...
Other Topics
best commercial firewalls
Dialup connection problems
how many people use ISP software?
Broadband Connection help
Best gaming modem
Moderators Wanted!!
Is Aol is best for Gaming?
Norton or AVG?
firewall problems
Internet Accelerator
Other Forums
Hardware/ Networking and All Operating Systems (Windows 98/XP/MAC/Linux)
Technical Questions & Answers
Tips & Tricks
Author
Message
ViroDoc!
Guest



Posts: 59716

Offline

PostPosted: Sat Jul 10, 2004 4:28 pm    Post subject: Sasser.A Sasser.B Sasser. C & D Reply with quote

This worm spreads by internet exploiting MS Windows LSASS service vulnerability described in MS Security Bulletin MS04-011.

I-Worm/Sasser.A
Installation:
When the worm is launched it copies itself as avserve.exe to Windows Directory and registers itself as avserve.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

I-Worm/Sasser.B
Installation:
When the worm is launched it copies itself as avserve2.exe to Windows Directory and registers itself as avserve2.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

I-Worm/Sasser.C
Installation:
When the worm is launched it copies itself as avserve2.exe to Windows Directory and registers itself as avserve2.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

I-Worm/Sasser.D
Installation:
When the worm is launched it copies itself as skynetave.exe to Windows Directory and registers itself as skynetave.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

I-Worm/Sasser.E
Installation:
When the worm is launched it copies itself as lsasss.exe to Windows Directory and registers itself as lsasss.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

I-Worm/Sasser.F
Installation:
When the worm is launched it copies itself as napatch.exe to Windows Directory and registers itself as napatch.exe in Run key in Windows Registry.

Spreading: internet
Worm searches IP addresses and when it finds a vulnerable computer it uses the exploit for downloading a copy of itself and its launching.

Removing:
Download and install latest Windows Patch resolving LSASS vulnerability from these pages or from Windows Update pages. You have to choose your operating system and language of your Windows.

The detected files content I-Worm/Sasser has to be deleted or use this remover.

If it isn`t possible to delete these files in Normal mode, run Windows in Safe mode (restart your computer, press and hold the F8 key during the initial Windows and choose SAFE mode option) and do following:
- move your cursor on Start bar
- press Start button -> Run -> write "regedit" without quotes
- press button OK
- please open the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- in the right column look for:
avserve.exe = %WinDir%\avserve.exe
or
avserve2.exe = %WinDir%\avserve2.exe
or
skynetave.exe = %WinDir%\skynetave.exe
or
lsasss.exe = %WinDir%\lsasss.exe
or
napatch.exe = %WinDir% apatch.exe
%WinDir% is name of your system folder (eg. WinNT, Windows)
- click by right button on the particular values and choose Delete
- close registry editor
- it`s required to delete following files:
%WinDir%\avserve.exe
or
%WinDir%\avserve2.exe
or
%WinDir%\skynetave.exe
or
%WinDir%\lsasss.exe
or
%WinDir% apatch.exe
depends on the path which was written in the registry
- Now you can restart your computer to normal mode again.

Note:
Immediately as you connect to Internet and your system isn`t updated by the latest patch from Microsoft, the virus will be activated again!

source: http://free.grisoft.com/freeweb.php/lng/us/doc/Virus+Encyclopaedia/tpl/v5/idn/086fdab66b76a000
 
Display posts from previous:   
Post new topic   Reply to topic     ISP Guide -> ISP Guide Forum Index -> Internet Utilities & Software All times are GMT - 6 Hours
Email this topic to a friend

Page 1 of 1
ISP Disscussion Topics

Main Forum Category
 
Other Network Forums
 •  ISP Discussions & Reviews
 •  ISP Technical Support
Broadband ISP Discussion
Forum Announcements and Site Reviews
 
 • Broadband Forum  
 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Related topics
 Topics   Replies   Author   Views   Last Post 
No new posts Cant connect it says line busy but phone line is OK. 9 Sam 3127 Wed Nov 24, 2004 12:43 am
Guest
No new posts isp connection error: error 650 when trying to connect isp 6 guest 7971 Thu Nov 04, 2004 10:00 pm
Guest
No new posts i cant connect 3 johnny 5113 Tue Jul 27, 2004 10:53 pm
Guest
No new posts AOL Starts when I try to connect? 2 Curt 1655 Wed Jun 23, 2004 8:09 am
Curt
No new posts How do I connect my wireless card to a wireless network? 1 joe 2579 Tue Jun 22, 2004 6:30 pm
robinson
 



Premium Network Of Directories
Affiliate Resources
Free Web Directory
Call to India
Domain-Name Registration
Web Hosting Provider
ISP Providers
Free Downloads
Broadband Internet
Outsourcing company Directory
Data Recovery Guide
Affiliate Resources
Call to Mexico
 
Other Internet Resources: ISP Resources