Shoutbox

New Virus Exploiting Microsoft Holes - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: New Virus Exploiting Microsoft Holes (/showthread.php?tid=24636)

New Virus Exploiting Microsoft Holes by matty on 05-02-2004 at 03:46 AM

Microsoft Windows LSASS Buffer Overrun Vulnerability

Description

Microsoft Windows LSASS (Local Security Authority Subsystem Service) is prone to a remotely exploitable buffer overrun vulnerability. Successful exploitation of this issue could allow a remote attacker to execute malicious code on a vulnerable system, resulting in full system compromise.

This issue could be exploited by an anonymous user on Microsoft Windows 2000 and XP operating systems. The issue may reportedly only be exploited by local, authenticated users on Microsoft Windows Server 2003 and Microsoft Windows XP 64-Bit Edition 2003.

Symantec Vulnerability Assessment
Symantec Vulnerability Assessment detects and reports this vulnerability. Click here for the advisory released April 13, 2004.


http://securityresponse.symantec.com/avcenter/sec...Content/10108.html


Stupid Microsoft making everyone aware of their holes then people make viruses, well work will be busy next few months, I do tech support and heard there was 160 calls waiting :S

[Image: attachment.php?pid=236608]
Image credit to Matty.

----------------------------------------------------------------
Removal

Norton Removal Tool

Download the FxSasser.exe file from: http://securityresponse.symantec.com/avcenter/FxSasser.exe.
Save the file to a convenient location, such as your downloads folder or the Windows desktop, or removable media known to be uninfected.
To check the authenticity of the digital signature, refer to the "Digital signature" section later in this writeup.
Close all the running programs before running the tool.
If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
If you are running Windows Me or XP, then disable System Restore. Refer to the "System Restore option in Windows Me/XP" section later in this writeup for further details.

Caution: If you are running Windows Me/XP, we strongly recommend that you do not skip this step.

Double-click the FxSasser.exe file to start the removal tool.
Click Start to begin the process, and then allow the tool to run.
Restart the computer.
Run the removal tool again to ensure that the system is clean.
If you are running Windows Me/XP, then re-enable System Restore.
Run LiveUpdate to make sure that you are using the most current virus definitions.


Disable System Restore Windows ME
Click Start
Click Settings
Click Control Panel
Double Click System
Click Preformance Tab at the top
Click File System
Click Troubleshooting Tab at the top
Check Disable System Restore (last box)
Click Ok, then Ok again

Disable System Restore Windows XP
Click Start
Click Run
Type "control panel" (without the quotes)
If in Category View(Says Pick a Category at the top) Click on System
If in Classic View (All icons shown) Double Click System
Click the System Restore tab at the top
Check the box that says Turn off System Restore on all drives.
You will be prompted and asked if you are sure and that all restore points will be deleted, Click Yes
Then click Apply, then Click OK

IF BY ANY CHANCE IN THE PROCESS OF DOING THIS THE BOX TO SHUT DOWN YOUR COMPUTER POPS UP DO THE FOLLOWING...
Click Start
Click Run
type "shutdown -a" (without the quotes)

Then Run the Removal Tool From Norton

After you have Run the Patch
Download and install the Microsoft update from here
(This Patch is for Windows XP Home and Pro with and without SP1)
For other Operating Systems please visit here

------------------------------
Variants

W32.Sasser.Worm
W32.Sasser.B.Worm
W32.Sasser.C.Worm


RE: New Virus Exploiting Microsoft Holes by Patchou on 05-02-2004 at 04:50 AM

Bha.. don't worry about it, IT guys always take those things way too seriously. As for Microsoft publishing this kind of information, that's because they released a patch so anyone who is scared can secure himself easily. If they don't publish the info, they get accused of hidding things.

Thanks for the post.


RE: New Virus Exploiting Microsoft Holes by Jordan2004 on 05-02-2004 at 11:31 AM

quote:
Originally posted by Patchou
Bha.. don't worry about it, IT guys always take those things way too seriously.

Agreed Patch. (Y)

Even though this is a very serious and quick spreading virus, there is already a patch for this on Windows Update (for affected operating systems), and virus definition are already updated. Therefore anyone who keeps their system up-to-date is not really going to be affected.

That's generally all users really need to do to combat viruses at the moment.
RE: New Virus Exploiting Microsoft Holes by tomfletcherman on 05-02-2004 at 03:02 PM

My firewalls just blocked three trojans, probably that :|


RE: New Virus Exploiting Microsoft Holes by Mike on 05-02-2004 at 07:51 PM

Hmmm...
I got this shutdown message today about Issas.exe being closed but after the 60 secs, computer didnt shutdown :rolleyes:
If I was going to the shutdown button on xp it was showing the log of screen.
When i clicked log off it stayed at "Saving your settings" and i had to close my computer with the hard way...

But after that i didnt got the same thing....

Btw wasnt blaster doing the same thing?


RE: New Virus Exploiting Microsoft Holes by matty on 05-02-2004 at 09:08 PM

quote:
Originally posted by Mike2
Hmmm...
I got this shutdown message today about Issas.exe being closed but after the 60 secs, computer didnt shutdown :rolleyes:
If I was going to the shutdown button on xp it was showing the log of screen.
When i clicked log off it stayed at "Saving your settings" and i had to close my computer with the hard way...

But after that i didnt got the same thing....

Btw wasnt blaster doing the same thing?

Yes it was doing the same thing, but these are two totally different viruses.

RE: New Virus Exploiting Microsoft Holes by Maniac on 05-03-2004 at 12:24 AM

Who cares, if you get that weird shutting off error, open a DOS command type "shutdown -a" then take ur type to get all the patches and ull be clear :p


RE: New Virus Exploiting Microsoft Holes by tomfletcherman on 05-03-2004 at 08:38 AM

I had 87 attempts to put that on my pc yesterday


RE: New Virus Exploiting Microsoft Holes by mgt on 05-03-2004 at 08:45 AM

Stupid Microsoft making everyone aware of their holes then people make viruses, well work will be busy next few months, I do tech support and heard there was 160 calls waiting

i had 10 calls :~(


RE: New Virus Exploiting Microsoft Holes by Wabz on 05-03-2004 at 09:23 AM

quote:
Originally posted by mgt
Stupid Microsoft making everyone aware of their holes then people make viruses, well work will be busy next few months, I do tech support and heard there was 160 calls waiting

i had 10 calls :~(


Hmmmm  I remembr the blaster worm I don't do tech support but i was getting phoned every 30 seconds from friends asking what was happening
RE: New Virus Exploiting Microsoft Holes by Pipish on 05-03-2004 at 10:08 AM

sound serious and freaky lol i hope i dont get it thanks for that info


RE: New Virus Exploiting Microsoft Holes by Mike on 05-03-2004 at 11:27 AM

But is this a virus?Because it doesnt sound like a virus to me... :undicided:


RE: New Virus Exploiting Microsoft Holes by Tochjo on 05-03-2004 at 11:33 AM

quote:
Originally posted by Mike2
But is this a virus?Because it doesnt sound like a virus to me... :undicided:
It is a virus, why do you think it isn't?
RE: New Virus Exploiting Microsoft Holes by Sunshine on 05-03-2004 at 12:16 PM

I don't think we have much to fear..the warning was to install a patch that has been released some time ago already. Also if u keep ur antivirusprogram up to date ur most likely protected against it already.

Also handy is  AVERT Stinger it scans for virusses/trojans/worms an related items...
get it here: http://vil.nai.com/vil/stinger/
(it found a few items my AV didnt :( )

Ohh yeah..what's sasser? It's a worm.


RE: New Virus Exploiting Microsoft Holes by tomfletcherman on 05-03-2004 at 02:53 PM

It allows a remote attacker to run malicious code on your pc, so it's kinda a virus


RE: RE: New Virus Exploiting Microsoft Holes by Sunshine on 05-03-2004 at 03:03 PM

quote:
Originally posted by tomfletcherman
It allows a remote attacker to run malicious code on your pc, so it's kinda a virus


Asfar as i know all it does is cause errormessages an reboots ur comp.
RE: New Virus Exploiting Microsoft Holes by Ezra on 05-03-2004 at 06:10 PM

If you type SHUTDOWN -s -t 01 at Run the same thing happends...


RE: New Virus Exploiting Microsoft Holes by JoeX on 05-03-2004 at 08:38 PM

Microsoft always give crap names To these things, Why cant they just give them the proper names, Ask the owner or something what they called it.

Just give them names like, For Example "NetSky"

But they called the newest one:

W32.NetSky.AB,  Always having to give them big names, Which are very pointless. Just confuses people who do not know anything about viruses,

As for me, I just let them Be, If they break my PC, Then Just format, I now have a virus scanner, So it takes the problems away, So... That should be a good thing,

So In otherwords.

Microsoft SUCK


RE: New Virus Exploiting Microsoft Holes by Kryptonate on 05-03-2004 at 08:46 PM

quote:
Originally posted by JoeX
Microsoft always give crap names To these things, Why cant they just give them the proper names, Ask the owner or something what they called it.

Just give them names like, For Example "NetSky"

But they called the newest one:

W32.NetSky.AB,  Always having to give them big names, Which are very pointless. Just confuses people who do not know anything about viruses,

1. Microsoft does not give these viruses a name, AV companies do. Making virusses is illegal, so they couldn't just ask the creator what name he/she gave it :p.
2. If they would just call it "Netsky" you wouldn't know which version you have. Every new version has a slight change in it, so it's best to know if a specific removal tool works for the version you might have.


quote:
Originally posted by JoeX
As for me, I just let them Be, If they break my PC, Then Just format, I now have a virus scanner, So it takes the problems away, So... That should be a good thing,

most people don't like to "just format" as they lose a lot of data in that way (especially if they haven't made a back up of their files).
A virus scanner is good but it's not waterproof, if you go and open every file you get by e-mail or so you have a big change of getting a new virus which hasn't been added to your virus definitions yet. You should always be carefull on the internet.

edit: no need to double post :)
RE: New Virus Exploiting Microsoft Holes by fluffy_lobster on 05-04-2004 at 04:06 PM

quote:
Originally posted by Sunshine
Asfar as i know all it does is cause errormessages an reboots ur comp.
It also spreads itself.  Which involves up to 1024 processes simultaneously and indefinitely picking random IP's and trying to infect the computer on that ip with the virus.  No wonder computers get error messages and reboot.  You can't do anything with it.

RE: New Virus Exploiting Microsoft Holes by TedoDude on 05-04-2004 at 04:10 PM

There is also a new virus - mainly came today - called Sasser - it targets a security patch downloaded from Microsoft Windows Update. Go to http://windowsupdate.microsoft.com to have a scan to see if you need a patch to sort it out :)

* TedoDude is being helpful today :P


RE: New Virus Exploiting Microsoft Holes by KnightieBoy on 05-04-2004 at 05:09 PM

quote:
Originally posted by TedoDude
There is also a new virus - mainly came today - called Sasser - it targets a security patch downloaded from Microsoft Windows Update. Go to http://windowsupdate.microsoft.com to have a scan to see if you need a patch to sort it out :)

* TedoDude is being helpful today :P
hmm isn't the first post about this too? well http://www.waarschuwingsdienst.nl (dutch) emailed to tell me to update, but I guess I already installed the update... otherwise I could also block ports 445, 5554, 9996 TCP or something :S
RE: New Virus Exploiting Microsoft Holes by TedoDude on 05-04-2004 at 05:26 PM

Not from what I have heard from the ICT guys in the office...


RE: New Virus Exploiting Microsoft Holes by Menthix on 05-04-2004 at 06:36 PM

quote:
Originally posted by Patchou
don't worry about it, IT guys always take those things way too seriously.
Uhmm... For what i heard there are already viruses on the loose which work kinda like Blaster did. Which means you can get infected by just being connected to the internet and doing notjing at all. Which i a thing people should serously protect themselves for. A good virusscanner in combinating with regular Windows Update saves you from A LOT of troubles.

quote:
Originally posted by VGProManiac
if you get that weird shutting off error, open a DOS command type "shutdown -a" then take ur type to get all the patches and ull be clear 
Also don't forget to run a good anti virus to be sure you weren't already been infected by other viruses before you fixed it all.

quote:
Originally posted by mgt
Stupid Microsoft making everyone aware of their holes then people make viruses
Microsoft makes people aware in order to get people install their fixes, a prefect fix is already availible on Windows Update for a few weeks. People in general should learn to update their PC on regular basis for their own good.

quote:
Originally posted by JoeX
Just give them names like, For Example "NetSky"
The official name is W32.NetSky, and with .AB they are pointing out a specific variant of this virus. So i think they call it perfectly by it's name.

quote:
Originally posted by JoeX
If they break my PC, Then Just format, I now have a virus scanner, So it takes the problems away
That's like "I don't lock my doors, if somebody breaks into my house i just but a new house.". Running Windows Update once a week/month, or just automatically is way less work then having to format your whole PC. And keep in mind that a virusscanner will not always block everything.


RE: New Virus Exploiting Microsoft Holes by fluffy_lobster on 05-04-2004 at 07:02 PM

Heh over here the news companies have been saying all day "Sasser is unlike other viruses because it travels over the internet rather than by email".  I get home and my dad tells me not to go on any websites and if i have to close them, not leave them open :lol:

The news can be so misleading


RE: New Virus Exploiting Microsoft Holes by Menthix on 05-04-2004 at 07:25 PM

:lol: Yes, oh well i had two free days :D. I hope the other network admin at work took care of the most problems and user questions. But i already know by now that i will defenitly will get such questions too.

The news should be a little more educational and tell people that they should simply:
- go to windowsupdate.microsoft.com and install the critical updates there on a regular basis.
- Install a good virusscanner and keep that one up-to-date and ensure it's configured right so it is actually scanning.

Yes, there are people i helped who only had their virusscanner configured for on-demand scanning :d.