Sasser: on a computer near YOU
p2pnet.net News:- If you’re worried your system is about to be ravaged by the W32/Sasser-A, W32/Sasser-B, and W32/Sasser-D worms which are now burrowing their way through the Net, you may have good reason.
Sasser is a self-executing network worm. Unfortunately, though, this doesn’t mean it’s suicidal. Rather, it means you don’t have to do anything to set it off and unlike most of the other deadly e-bugs that have been appearing lately, it doesn’t need email to spread.
Instead, it moves around online thanks to the gaping Microsoft Windows vulnerability MS04-011.
Microsoft has a web site here with all the do’s and don’ts, but the brutal, bottom line reality is:
If you’re Microsoft Windows XP or Windows 2000 user and you haven’t kept on top of all of the Microsoft Windows ’security’ fixes and patches Bill and the Boyz seem to issue every 10 minutes of so, Sasser is going to get you.
It spreads to Windows PCs automatically, even if no-one’s using the PC at the time, and once a machine is infected, the e-worm moves on to other computers and as a side effect, users might see error messages and experience repeated reboots.
If you’re running W2k or XP and haven’t updated Windows recently, DON’T GO ONLINE WITHOUT A FIREWALL of some kind.
If you’ve been burrowed, patch the LSASS hole first, then remove the worm – otherwise the worm could reinfect you immediately.
A free tool to remove the Sasser.A and Sasser.B worms is available here.
Go here for more info from Microsoft.
Either that, or buy a Mac ; ).






May 6th, 2004 at 12:40 am
it’s ugly i know quite a few people now who got it
good way to make some extra cash thou helping people get their systems back from all these virii
May 6th, 2004 at 3:48 am
Most firewalls stop unauthorized incoming traffic so as long as you have not opened up the ports used by Sasser you should be fine even without Microsoft’s patch.
May 6th, 2004 at 6:52 am
lol true but most arent closing ports. How many people actually define rules in their firewall beyond the default settings? How many know how to close ports on their machines? not many, even the more security conscience I know wait for symantec et al to do virus updates. Not many people who are into prevention rather than cure. I still get firewall hits from Blaster, that happened last August, you’d think that problem would be gone now…just goes to show people would rather someone else fix the problem rather than understand the root of the problem.
BTW this time microsoft released the patch 18 days before sasser reared it’s ugly head…