Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | [Merged] W32/Sasser.worm


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

[Merged] W32/Sasser.worm
Reply
 
Thread Tools
Old 01-05-2004, 19:58   #1
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,474
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
[Merged] W32/Sasser.worm

FYI;

Quote:
Advisory
This is a Medium Threat Advisory for W32/Sasser.worm

Justification
W32/Sasser.worm has been deemed Medium due to prevalence

Read About It
Information about W32/Sasser.worm is located on VIL at:
http://vil.nai.com/vil/content/v_125007.htm

Detection
W32/Sasser.worm was first discovered on 30/04/2004 and detection will be added to the 4355 dat files (Release Date: 01/05/2004). The EXTRA.DAT is available.
This exploits a hole covered in the latest MS patch - MS04-011.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 01-05-2004, 20:03   #2
cf.geek
 
Alan Waddington's Avatar
 
Join Date: Jun 2003
Location: Farnham
Posts: 503
Alan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about themAlan Waddington has a spectacular aura about them
Re: W32/Sasser.worm

Thanks for the heads up. I've really got to watch the viruses at the moment because someone who has me in their address book has got a NetSky & i keep being gifted with them

Well, Sasser's in my normal virus update i got today from norton, so no need to manually install the extra definitions.
Alan Waddington is offline   Reply With Quote
Old 03-05-2004, 11:41   #3
WooooooooooOOoooSH!!!
 
DrAwesome's Avatar
 
Join Date: Jun 2003
Location: I dwell within bricks & morta
Posts: 2,268
DrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond reputeDrAwesome has a reputation beyond repute
Send a message via AIM to DrAwesome Send a message via MSN to DrAwesome
Cool Re: W32/Sasser.worm

This Link may be useful to someone :0)
DrAwesome is offline   Reply With Quote
Old 04-05-2004, 21:39   #4
cf.addict
 
Join Date: Jul 2003
Posts: 320
50420 is a name known to all50420 is a name known to all50420 is a name known to all50420 is a name known to all50420 is a name known to all50420 is a name known to all50420 is a name known to all50420 is a name known to all
sasser worm...have ntl blocked these ports?

hi all....apologies if this is being discussed elsewhere...but couldnt find the subject when searched the forums.

just a queery really regarding the sasser alert on the ntl homepage
http://www.ntlworld.com/help/aup/virus_sasser.php

going by the wording of the alert...it sounds as if the relevant ports have been blocked??

more info here on sasser http://securityresponse.symantec.com...er.b.worm.html

only reason i'm askin is cos of a thread on the computeractive forums.....where a poster has accused ntl of crass incompetance and stupidity for informing thier customers that they are not susceptible to sasser. (this aint what is stated in the alert though !!!!) the alert states that MOST ntl cusomers SHOULD not be susceptible to it due to proactive measures.
__________________
"This product that was on TV was available for four easy payments of $19.95. I would like a product that was available for three easy payments and one complicated payment. We can't tell you which payment it is, but one of these payments is going to be hard."
50420 is offline   Reply With Quote
Old 04-05-2004, 21:44   #5
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 20
Services: BT, Sky multiroom (Sky+ & HD), UKOnline 8MB ADSL
Posts: 6,138
MadGamer has a bronzed appealMadGamer has a bronzed appeal
MadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appealMadGamer has a bronzed appeal
Re: sasser worm...have ntl blocked these ports?

I know M$ have a patch but i can't find it.
__________________
XBL Gamertag: MadGamer1988

MadGamer is offline   Reply With Quote
Old 04-05-2004, 21:51   #6
cf.member
 
Join Date: Nov 2003
Location: Edgbaston, West Mids
Services: VM 20mb. Over subscribed UBR...wooot, Great huh!
Posts: 33
BizBo is an unknown quantity at this point
Re: sasser worm...have ntl blocked these ports?

Patch from Microsoft
BizBo is offline   Reply With Quote
Old 04-05-2004, 21:53   #7
cf.mega poster
 
jellybaby's Avatar
 
Join Date: Jun 2003
Location: peterborough
Services: TV, Phone, BB 20meg(CM 250) - VM
Posts: 1,729
jellybaby has a bronzed appealjellybaby has a bronzed appeal
jellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appealjellybaby has a bronzed appeal
Send a message via AIM to jellybaby Send a message via MSN to jellybaby Send a message via Skype™ to jellybaby
Re: sasser worm...have ntl blocked these ports?

And Here is quite useful too
jellybaby is offline   Reply With Quote
Old 04-05-2004, 21:55   #8
I am not a geek!
 
philip.j.fry's Avatar
 
Join Date: Jul 2003
Posts: 1,395
philip.j.fry has reached the bronze age
philip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze agephilip.j.fry has reached the bronze age
Re: [Merged] W32/Sasser.worm

And what a pain this virus is, it infected the uni computer system this morning just as I was giving a demonstration of my dissertation project so the computer kept crashing
philip.j.fry is offline   Reply With Quote
Old 04-05-2004, 21:56   #9
Cable Forum Team
 
Matt D's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Age: 31
Services: Freeview, Sky+HD, Sky Broadband "Max", BT phone
Posts: 10,377
Matt D has a nice shiny starMatt D has a nice shiny starMatt D has a nice shiny star
Matt D has a nice shiny star
Re: sasser worm...have ntl blocked these ports?

Quote:
Originally Posted by 50420
hi all....apologies if this is being discussed elsewhere...but couldnt find the subject when searched the forums.
I've merged your thread with the Sasser thread in the Security forum

Quote:
just a queery really regarding the sasser alert on the ntl homepage
http://www.ntlworld.com/help/aup/virus_sasser.php
Don't know if NTL have blocked the ports. Maybe one of our NTL-employed members will be able to answer that.
__________________
My Blog - My Photo Gallery

Xbox Live Gamertag - Tezcatlipoca | PSN ID - Mister_Tez | NTHW PC Gaming Clan
Matt D is offline   Reply With Quote
Old 04-05-2004, 21:58   #10
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,474
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: sasser worm...have ntl blocked these ports?

Quote:
Originally Posted by WNA
I know M$ have a patch but i can't find it.
The patches are in the "Latest Microsoft Patches" announcement in the Computers & Technology forums (at the top of the topics list).
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 07-05-2004, 17:36   #11
Inactive
 
Join Date: Jan 2004
Posts: 66
porpoise is an unknown quantity at this point
sassa worm

I got the sassa worm !!! My son wnet onto symantec and downloaded the removal tool for me. I've now got rid of it. I went on to windows update and It said download this update to stay clear of the sassa worm, I checked my history and i'd downloaded it on April 14th !!! Also my son said that I can go into msconfig and get Zonealarm to start earlier in the start up menu ??? how ???
porpoise is offline   Reply With Quote
Old 07-05-2004, 18:05   #12
cf.addict
 
Join Date: Feb 2004
Location: UK
Age: 31
Services: 20 MB Broadband and Phone
Posts: 171
byron_hinson is an unknown quantity at this point
Send a message via MSN to byron_hinson
Re: [Merged] W32/Sasser.worm

I've noticed CPU Spikes when I am connected to the internet over the last 2 days - any ideas if this is the virus looking for IP Addresses - my machines and clean and all up to date, just can't figure this one out.
byron_hinson is offline   Reply With Quote
Old 07-05-2004, 18:38   #13
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 24
Services: Virgin Media Broadband Size M
Posts: 6,849
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: [Merged] W32/Sasser.worm

Quote:
Originally Posted by byron_hinson
I've noticed CPU Spikes when I am connected to the internet over the last 2 days - any ideas if this is the virus looking for IP Addresses - my machines and clean and all up to date, just can't figure this one out.
when you say connecting to the internet, is that using a dial or BB connection? and what exactly do you mean by connecting to the internet? is it opening IE? or any program?
__________________
Chinese Proverb: Man who walks round with hand in pocket feels cocky all day.
Chris W is offline   Reply With Quote
Old 07-05-2004, 19:22   #14
cf.addict
 
Join Date: Feb 2004
Location: UK
Age: 31
Services: 20 MB Broadband and Phone
Posts: 171
byron_hinson is an unknown quantity at this point
Send a message via MSN to byron_hinson
Re: [Merged] W32/Sasser.worm

Wireless broadband. Don't have to be running any programs at all for it to show up the problem. if i switch off the wireless connection then everything is fine.
byron_hinson is offline   Reply With Quote
Old 08-05-2004, 09:20   #15
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 24
Services: Virgin Media Broadband Size M
Posts: 6,849
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Sasser Virus Arrest

Just heard that someone has been arrested for the Sasser virus....

not much news yet, just breaking on news24. 18 year old from Germany who wrote and activated that virus on his own.

Good to see that the person responsible has been caught
__________________
Chinese Proverb: Man who walks round with hand in pocket feels cocky all day.
Chris W is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 06:54.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)