PDA

View Full Version : sasser fix



djpo
05-25-2004, 11:42 PM
1. To end the malicious process
To end the malicious process:

a. Press Ctrl+Alt+Delete once.

b. Click Task Manager.

c. Click the Processes tab.

d. Double-click the Image Name column header to alphabetically sort the processes.

e. Scroll through the list and look for the following processes:

• avserve2.exe
• any process with a name consisting of 4 or 5 digits followed by _up.exe (eg 74354_up.exe).

f. If you find any such process, click it, and then click End Process.

g. Exit the Task Manager.

Tp get rid of the key

a. Click Start, and then click Run. (The Run dialog box appears.)
b. Type regedit

Then click OK. (The Registry Editor opens.)
c. Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
d. In the right pane, delete the value:

"avserve2.exe"="%Windir%\avserve2.exe"

ALF_II
05-27-2004, 10:40 AM
I didn't have sasser but my computer was shutdown every now and then and I didn't know how to stop that.
The firewall stopped the port scanning and executing the svchost.exe on my computer and the attack of the nasty ntoskrnl.exe.
It seems some computers are hosts for the worm and some are victims.
It is very clear that no one is able to figure out what is going on - at least in this forum.