new worm rebooting computers

Wargasm

Ultra Cool Member
Reaction score
50
http://www.microsoft.com/security/incident/sasser.asp

Load up your firewall. Check the above link for info and removal tools .

If you don't stay up-to-date on these patches and/or run a firewall, you are part of the problem! Get with the program people. There are no excuses any more! I'll bet it won't be long before countries make laws holding users liable for not protecting their systems and maybe even confiscating their PCs!
 
Note: www.microsoft.com/technet/security and www.microsoft.com/security are
authoritative in all matters concerning Microsoft Security Alerts! ANY
e-mail, web board or newsgroup posting (including this one) should be
verified by visiting these sites for official information. Microsoft never
sends security or other updates as attachments. These updates must be
downloaded from the microsoft.com download center or Windows Update. See the
individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft
security notices, it is recommended that you physically type the URLs into
your web browser and not click on the hyperlinks provided.

Instructions for patching and cleaning vulnerable Windows 2000 and Windows
XP systems:

Vulnerable Windows 2000 and Windows XP machines may have the LSASS.EXE
process crash every time a malicious worm packet targets the vulnerable
machine which can occur very shortly after the machine starts up and
initializes the network stack.

When cleaning a machine that is vulnerable to the Sasser worm it is
necessary to first prevent the LSASS.EXE process from crashing, which in
turn causes the machine to reboot after a 60 second delay. This reboot
cannot be aborted on Windows 2000 platforms using the Shutdown.exe or
psshutdown.exe utilities and can interfere with the downloading and
installation of the patch as well as removal of the worm.

1. To prevent LSASS.EXE from shutting down the machine during the cleaning
process:
a. Unplug the network cable from the machine
b. If you are running Windows XP you can enable the built-in Internet
Connection Firewall using the instructions found here: Windows XP
http://support.microsoft.com/?id=283673 and then plug the machine back into
the network and go to step 2.

c. If you are running Windows 2000, you won't have a built-in firewall
and must use the following work-around to prevent LSASS.EXE from crashing.
This workaround involves creating a read-only file named 'dcpromo.log' in
the "%systemroot%\debug" directory. Creating this read-only file will
prevent the vulnerability used by this worm from crashing the LSASS.EXE
process.
i. NOTE: %systemroot% is the variable that contains the name
of the Windows installation directory. For example if Windows was installed
to the "c:\winnt" directory the following command will create a file called
dcpromo.log in the c:\winnt\debug directory. The following commands must be
typed in a command prompt (i.e. cmd.exe) exactly as they are written below.

1. To start a command shell, click Start and then click run and type
'cmd.exe' and press enter.

2.Type the following command:
echo dcpromo >%systemroot%\debug\dcpromo.log

For this workaround to work properly you MUST make the file read-only
by typing the following command:

3. attrib +R %systemroot%\debug\dcpromo.log


2. After enabling the Internet Connection Firewall or creating the read-only
dcpromo.log you can plug the network cable back in and you must download and
install the MS04-011 patch from the MS04-011 download link for the affected
machines operating system before cleaning the system. If the system is
cleaned before the patch is installed it is possible that the system could
get re-infected prior to installing the patch.
a. Here is the URL for the bulletin which contains the links to the
download location for each patch:
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
b. If your machine is acting sluggish or your Internet connection is
slow you should use Task Manager to kill the following processes and then
try downloading the patch again (press the Ctrl + Alt + Del keys
simultaneously and select Task Manager):

i. Kill any process ending with '_up.exe' (i.e. 12345_up.exe)
ii. Kill any process starting with 'avserv' (i.e. avserve.exe,
avserve2.exe)
iii. Kill any process starting with 'skynetave' (i.e. skynetave.exe)
iv. Kill hkey.exe
v. Kill msiwin84.exe
vi. Kill wmiprvsw.exe


1. Note there is a legitimate system process called 'wmiprvse.exe' that
does NOT need to be killed.
c. allow the system to reboot after the patch is installed.


3. Run the Sasser cleaner tool from the following URL:
a. For the on-line ActiveX control based version of the cleaner you can
run it directly from the following URL:
http://www.microsoft.com/security/incident/sasser.asp

b. For the stand-alone download version of the cleaner you can download
it from the following URL:

http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en

4. Determine if the machine has been infected with a variant of the Agobot
worm which can also get on the machine using the same method as the Sasser
worm.
a. To do this run a full antivirus scan of your machine after ensuring
your antivirus signatures are up to date.
b. If you do NOT have an antivirus product installed you can visit
HouseCall from TrendMicro to perform a free scan using the following URL:
http://housecall.trendmicro.com/
 
rap u got too much time hehehe

and hey we got a copyright problem right here ..
it is normally me who lashes out and tell ppl to stick with the program heheh
now your ranting hehe

it's the other side of the medal
u had tons of fixing todo prolly
while i could charge every idiot errr i mean user 50 bucks


i can only say it was not a bad week hehehe
 
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Varine Varine:
    Today I had to scramble, I didn't work most of dinner service and no one told me shit. They had a rough few hours lol
  • Varine Varine:
    I have two salmon, Sockeye and Atlantic. Atlantic is used for the kids salmon and the salmon and beet salad, and can also be added onto any dish or just as a side. Atlantic salmon will almost exclusively ever be FARMED, as it is endangered in the wild, and we ALWAYS cut them to 4 ounces.
  • Varine Varine:
    SOCKEYE salmon, very different and this IS wild caught. We have an ENTREE version, and an add on version. The entree is 7 ounces, the add on is 4. Why? Because that is how someone that wasn't me set up the computer.
  • Varine Varine:
    I had to have this conversation like ten fucking times tonight
  • Varine Varine:
    The issue being, I came into work and had none of this whatsoever
  • Varine Varine:
    No one told me shit
  • Varine Varine:
    So, taking into consideration that what I typed out up there is kind of some fucking nonsense that under normal circumstances no one really needs to fucking be able to explain in any rational way
  • Varine Varine:
    Let alone trying to figure it out from a wildly stressed out me that is also on a phone call trying to get something to show up from Seattle tomorrow while trying to explain this salmon situation, that also is barely solved in maybe a few hours and and but I am bulking it with a few steelhead filets I have and that is a WHOLE fucking different thing to the 19 year old server that got put on day shift C crew that doesn't know who I am.
  • Varine Varine:
    I did however really want days. I like getting off at 4 half the time, and that makes it worth it!
  • Varine Varine:
    Also I hate my job right now but I think that was the hard part. Now it's just work
  • Varine Varine:
    @jonas I'm sorry? I don't know what you're referring to.
  • Varine Varine:
    Once we hit winter I feel like I get to back to having a pretty cool job. Like I bitch about it all the time, but it's work. I'm still gonna bitch
  • Varine Varine:
    All in all though I think this summer is going really well. Some complicated things, but at the end of the day it isn't THAT big of a deal. Not all of our servers have quite realized they are technically sales
  • Varine Varine:
    Like yeah it is a substitute, but FOMO. Chef isn't getting this again this year, he has to figure it out, so it's slightly off on the menu, but that is more or less the LOWEST quality and price. Right now, steelhead is a real stealhear, right?
  • Varine Varine:
    Like fuck off even I can do it
  • Varine Varine:
    I am going to get one of my servers to do that in her server voice and you'll see my point
  • Varine Varine:
    Maybe the bartender. Idk, it's one of my favorite things to hear them go from calm to customer service voice. They will translate it to like "The chef is trying to change that a bit right now so he does have a Alaskan river steelhead. Yeah like the one you might fish probably!" And then the girls can bat their eyes and do pretty girl server shit
  • Varine Varine:
    At least that's how imagine some of them. Did you know mayonnaise is dairy free? A suprisingly amount of people don't\
  • The Helper The Helper:
    mayo is eggs right?
  • The Helper The Helper:
    Seems I never watched the Witcher - looks like i have a lot of content
  • The Helper The Helper:
    Season 1 Episode 8 the marathon continues...
  • jonas jonas:
    mayo is eggs & oil
    +1
  • The Helper The Helper:
    I got halfway season 2 on The Witcher and it lost me. I am going to have to pick this one up again later.
  • jonas jonas:
    season 2 is with the new actor right? it's so far below the first one
  • The Helper The Helper:
    first season was good the 2nd season is bleh I hope I can make it through it for 3

      The Helper Discord

      Staff online

      • Ghan
        Administrator - Servers are fun

      Members online

      Affiliates

      Hive Workshop NUON Dome World Editor Tutorials
      Top