Re: Sasser: oldie but goodie
- From: "Duh_OZ" <ozzy.kopec@xxxxxxxxx>
- Date: 6 Mar 2007 14:37:34 -0800
On Mar 6, 3:48 pm, "David H. Lipman" <DLipman~nosp...@xxxxxxxxxxx>
wrote:
From: "Duh_OZ" <ozzy.ko...@xxxxxxxxx>Alas I wasn't in there to see anything in action but I did see he ran
| Had two dead motherboards (bad batch of Dell GX270s) replaced today
| and both machines got hit with the Sasser virus. Guess I better get a
| firewall to protect me from the corporate firewall? Tech did the
| work so didn't have the pleasure with dealing with it.
|
| I tried to check on windoze updates (running XP) on both the new
| motherboard machine and an old one. Friigen computers can't even
| connect to the update page. What a system LOL. Another box I am
| currently using the multi-av tool, just to be sure all is okay :0)
Ozzy:
Just need to know...
Is this TRULY a Sasser worm or was it another worm that was using the buffer overflow
explotation in LSASS via TCP port 445 ?
--
the Symantec W32.Sasser removal tool (and told me both got hit with
Sasser).
The Multi-AV just finished before I left and a very quick look at the
log showed a Zapchast and a trojan downloader was on the computer
(which have a trend-micro client).
I'll look at the file names and see if they have a match on the other
computer. I *think* one was c.bat(zapchast) in the /system folder.
Now, can I install multi-av on the other computer. I was able to do
it on the one as the tech hadn't signed off (us workers have no
administrative rights on the XP boxes). It's not that I don't trust
big brother to protect me, it's I just don't trust big brother to
protect me LOL.
.
- Follow-Ups:
- Re: Sasser: oldie but goodie
- From: David H. Lipman
- Re: Sasser: oldie but goodie
- References:
- Sasser: oldie but goodie
- From: Duh_OZ
- Re: Sasser: oldie but goodie
- From: David H. Lipman
- Sasser: oldie but goodie
- Prev by Date: Re: Sasser: oldie but goodie
- Next by Date: Re: Sasser: oldie but goodie
- Previous by thread: Re: Sasser: oldie but goodie
- Next by thread: Re: Sasser: oldie but goodie
- Index(es):
Relevant Pages
|