What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » New Virus Exploiting Microsoft Holes

New Virus Exploiting Microsoft Holes
Author: Message:
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
O.P. New Virus Exploiting Microsoft Holes
Microsoft Windows LSASS Buffer Overrun Vulnerability

Description

Microsoft Windows LSASS (Local Security Authority Subsystem Service) is prone to a remotely exploitable buffer overrun vulnerability. Successful exploitation of this issue could allow a remote attacker to execute malicious code on a vulnerable system, resulting in full system compromise.

This issue could be exploited by an anonymous user on Microsoft Windows 2000 and XP operating systems. The issue may reportedly only be exploited by local, authenticated users on Microsoft Windows Server 2003 and Microsoft Windows XP 64-Bit Edition 2003.

Symantec Vulnerability Assessment
Symantec Vulnerability Assessment detects and reports this vulnerability. Click here for the advisory released April 13, 2004.


http://securityresponse.symantec.com/avcenter/sec...Content/10108.html


Stupid Microsoft making everyone aware of their holes then people make viruses, well work will be busy next few months, I do tech support and heard there was 160 calls waiting :S

[Image: attachment.php?pid=236608]
Image credit to Matty.

----------------------------------------------------------------
Removal

Norton Removal Tool

Download the FxSasser.exe file from: http://securityresponse.symantec.com/avcenter/FxSasser.exe.
Save the file to a convenient location, such as your downloads folder or the Windows desktop, or removable media known to be uninfected.
To check the authenticity of the digital signature, refer to the "Digital signature" section later in this writeup.
Close all the running programs before running the tool.
If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
If you are running Windows Me or XP, then disable System Restore. Refer to the "System Restore option in Windows Me/XP" section later in this writeup for further details.

Caution: If you are running Windows Me/XP, we strongly recommend that you do not skip this step.

Double-click the FxSasser.exe file to start the removal tool.
Click Start to begin the process, and then allow the tool to run.
Restart the computer.
Run the removal tool again to ensure that the system is clean.
If you are running Windows Me/XP, then re-enable System Restore.
Run LiveUpdate to make sure that you are using the most current virus definitions.


Disable System Restore Windows ME
Click Start
Click Settings
Click Control Panel
Double Click System
Click Preformance Tab at the top
Click File System
Click Troubleshooting Tab at the top
Check Disable System Restore (last box)
Click Ok, then Ok again

Disable System Restore Windows XP
Click Start
Click Run
Type "control panel" (without the quotes)
If in Category View(Says Pick a Category at the top) Click on System
If in Classic View (All icons shown) Double Click System
Click the System Restore tab at the top
Check the box that says Turn off System Restore on all drives.
You will be prompted and asked if you are sure and that all restore points will be deleted, Click Yes
Then click Apply, then Click OK

IF BY ANY CHANCE IN THE PROCESS OF DOING THIS THE BOX TO SHUT DOWN YOUR COMPUTER POPS UP DO THE FOLLOWING...
Click Start
Click Run
type "shutdown -a" (without the quotes)

Then Run the Removal Tool From Norton

After you have Run the Patch
Download and install the Microsoft update from here
(This Patch is for Windows XP Home and Pro with and without SP1)
For other Operating Systems please visit here

------------------------------
Variants

W32.Sasser.Worm
W32.Sasser.B.Worm
W32.Sasser.C.Worm

.gif File Attachment: Sasser Worm.gif (7.44 KB)
This file has been downloaded 406 time(s).

This post was edited on 05-08-2004 at 04:20 PM by matty.
05-02-2004 03:46 AM
Profile E-Mail PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
New Virus Exploiting Microsoft Holes - by matty on 05-02-2004 at 03:46 AM
RE: New Virus Exploiting Microsoft Holes - by Patchou on 05-02-2004 at 04:50 AM
RE: New Virus Exploiting Microsoft Holes - by Jordan2004 on 05-02-2004 at 11:31 AM
RE: New Virus Exploiting Microsoft Holes - by tomfletcherman on 05-02-2004 at 03:02 PM
RE: New Virus Exploiting Microsoft Holes - by Mike on 05-02-2004 at 07:51 PM
RE: New Virus Exploiting Microsoft Holes - by matty on 05-02-2004 at 09:08 PM
RE: New Virus Exploiting Microsoft Holes - by Maniac on 05-03-2004 at 12:24 AM
RE: New Virus Exploiting Microsoft Holes - by tomfletcherman on 05-03-2004 at 08:38 AM
RE: New Virus Exploiting Microsoft Holes - by mgt on 05-03-2004 at 08:45 AM
RE: New Virus Exploiting Microsoft Holes - by Wabz on 05-03-2004 at 09:23 AM
RE: New Virus Exploiting Microsoft Holes - by Pipish on 05-03-2004 at 10:08 AM
RE: New Virus Exploiting Microsoft Holes - by Mike on 05-03-2004 at 11:27 AM
RE: New Virus Exploiting Microsoft Holes - by Tochjo on 05-03-2004 at 11:33 AM
RE: New Virus Exploiting Microsoft Holes - by Sunshine on 05-03-2004 at 12:16 PM
RE: New Virus Exploiting Microsoft Holes - by tomfletcherman on 05-03-2004 at 02:53 PM
RE: RE: New Virus Exploiting Microsoft Holes - by Sunshine on 05-03-2004 at 03:03 PM
RE: New Virus Exploiting Microsoft Holes - by Ezra on 05-03-2004 at 06:10 PM
RE: New Virus Exploiting Microsoft Holes - by JoeX on 05-03-2004 at 08:38 PM
RE: New Virus Exploiting Microsoft Holes - by Kryptonate on 05-03-2004 at 08:46 PM
RE: New Virus Exploiting Microsoft Holes - by fluffy_lobster on 05-04-2004 at 04:06 PM
RE: New Virus Exploiting Microsoft Holes - by TedoDude on 05-04-2004 at 04:10 PM
RE: New Virus Exploiting Microsoft Holes - by KnightieBoy on 05-04-2004 at 05:09 PM
RE: New Virus Exploiting Microsoft Holes - by TedoDude on 05-04-2004 at 05:26 PM
RE: New Virus Exploiting Microsoft Holes - by Menthix on 05-04-2004 at 06:36 PM
RE: New Virus Exploiting Microsoft Holes - by fluffy_lobster on 05-04-2004 at 07:02 PM
RE: New Virus Exploiting Microsoft Holes - by Menthix on 05-04-2004 at 07:25 PM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On