NT Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 05/29/12
· Microsoft Xbox 720 to feature in-game Skype integration
· Installing Lighttpd With PHP5 (PHP-FPM) And MySQL Support On Ubuntu 12.04
· CompatDB Updates 05/28/12
· Daily Reviews Summary 05/28/12
· GLSA 201205-04: Chromium, V8: Multiple vulnerabilities
· Daily Reviews Summary 05/26/12
· Microsoft Office for iPad reportedly on track for November release
· Aged Windows XP costs 5x more to manage than Windows 7
· Wine 1.5.5 released

Upcoming News
· Samsung SyncMaster S27B750 Monitor Review @ t-break
· [security-announce] openSUSE-SU-2012:0655-1: important: update for cobbler
· [security-announce] openSUSE-SU-2012:0656-1: important: update for chromium, v8
· Samsung Green DDR3 8GB 1600MHz 30nm Review @ Vortez
· Thermaltake Frio Extreme Cooler @ TechwareLabs
· Samsung UN46ES6500F Review @ TechReviewSource.com
· bits from the NM process: advocacy, no more AM reports, AMs needed
· Sitecom N750 X6 WLR-6000 Wireless Gigabit Router Review @ Madshrimps
· Mushkin Chronos Deluxe 120GB & Chronos 240GB SSD Review
· Home Income Everyday

Windows Compatibility
· IObit Malware Fighter
· IObit SmartDefrag
· Realtek High Definition Audio for 2K/XP/03
· Advanced SystemCare with Antivirus 2012
· Samsung Drive Diagnostic Utility (Hutil)
· Google Chrome 18.0.1025.168 Final
· Skype
· Advanced SystemCare Free 5.3.0.245 Final
· IObit SmartDefrag v2 Beta 3.0
· Atheros Wireless AR5B91 Driver

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Windows XP
· Microsoft
· Updates
· Interviews
· Windows Server 2003
· General
· Windows Vista
· Webcasts
· Windows Server 2008
· Windows Home Server
· Windows 7
· Windows 8
· Windows Phone 7

What's New
Login to see an overview of all news stories since your last visit.

Affiliates

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

NT Compatible » News » May 2004 » Sasser patching/clean up instructions

Sasser patching/clean up instructions

Posted by Philipp Esselbach on: 05/05/2004 04:03 AM [ Print | 0 comment(s) ]

Instructions for patching and cleaning vulnerable Windows 2000 and Windows XP systems:

Vulnerable Windows 2000 and Windows XP machines may have the LSASS.EXE process crash every time a malicious worm packet targets the vulnerable machine which can occur very shortly after the machine starts up and initializes the network stack.

When cleaning a machine that is vulnerable to the Sasser worm it is necessary to first prevent the LSASS.EXE process from crashing, which in turn causes the machine to reboot after a 60 second delay. This reboot cannot be aborted on Windows 2000 platforms using the Shutdown.exe or psshutdown.exe utilities and can interfere with the downloading and installation of the patch as well as removal of the worm.




1. To prevent LSASS.EXE from shutting down the machine during the cleaningprocess:

a. Unplug the network cable from the machine

b. If you are running Windows XP you can enable the built-in Internet Connection Firewall using the instructions found here: Windows XP

http://support.microsoft.com/?id=283673 and then plug the machine back into the network and go to step 2.

c. If you are running Windows 2000, you won't have a built-in firewall and must use the following work-around to prevent LSASS.EXE from crashing.

This workaround involves creating a read-only file named 'dcpromo.log' in the "%systemroot%\\debug" directory.

Creating this read-only file will prevent the vulnerability used by this worm from crashing the LSASS.EXE process.

i. NOTE: %systemroot% is the variable that contains the name of the Windows installation directory. For example if Windows was installed to the "c:\\winnt" directory the following command will create a file called dcpromo.log in the c:\\winnt\\debug directory. The following commands must be typed in a command prompt (i.e. cmd.exe) exactly as they are written below.

1. To start a command shell, click Start and then click run and type 'cmd.exe' and press enter.

2.Type the following command: echo dcpromo >%systemroot%\\debug\\dcpromo.log

For this workaround to work properly you MUST make the file read-only by typing the following command:

3. attrib +R %systemroot%\\debug\\dcpromo.log2. After enabling the Internet Connection Firewall or creating the read-only dcpromo.log you can plug the network cable back in and you must download and install the MS04-011 patch from the MS04-011 download link for the affected machines operating system before cleaning the system. If the system is cleaned before the patch is installed it is possible that the system could get re-infected prior to installing the patch.

a. Here is the URL for the bulletin which contains the links to the download location for each patch: http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx

b. If your machine is acting sluggish or your Internet connection is slow you should use Task Manager to kill the following processes and then try downloading the patch again (press the Ctrl + Alt + Del keys simultaneously and select Task Manager):

i. Kill any process ending with '_up.exe' (i.e. 12345_up.exe)
ii. Kill any process starting with 'avserv' (i.e. avserve.exe,avserve2.exe)
iii. Kill any process starting with 'skynetave' (i.e. skynetave.exe)
iv. Kill hkey.exe
v. Kill msiwin84.exe
vi. Kill wmiprvsw.exe

1. Note there is a legitimate system process called 'wmiprvse.exe' that does NOT need to be killed.

c. allow the system to reboot after the patch is installed.

3. Run the Sasser cleaner tool from the following URL:

a. For the on-line ActiveX control based version of the cleaner you can run it directly from the following URL: http://www.microsoft.com/security/incident/sasser.asp

b. For the stand-alone download version of the cleaner you can download it from the following URL: http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17displaylang=en4.

Determine if the machine has been infected with a variant of the Agobot worm which can also get on the machine using the same method as the Sasser worm.

a. To do this run a full antivirus scan of your machine after ensuring your antivirus signatures are up to date.

b. If you do NOT have an antivirus product installed you can visit HouseCall from TrendMicro to perform a free scan using the following URL: http://housecall.trendmicro.com/

If you have any questions regarding the security updates or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety (1-866-727-2338). International customers should contact their local subsidiary.


Bookmark and Share

Related Threads

05/12/2004 02:32 AM: Slow downloads and loss of network after MS Sasser Patch (0) by bobbinbrisco

« Changes to Functionality in Microsoft Windows XP Service Pack 2 · ATi's Richard Huddy - Some answers on the Radeon X800 »

NT Compatible » News » May 2004 » Sasser patching/clean up instructions
All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition