SingTel
SingNet
 
 
 
     

Internet Security - Virus - W32.Sasser.B.Worm
W32.Sasser.B.Worm
The W32.Sasser.B.Worm spreads by scanning random IP addresses for computer systems that have not patched the Microsoft LSASS vulnerability.

Systems Affected   Windows 2000, Windows XP and Windows Server 2003.
Symptoms  
  • Computer shuts down and/or reboots
  • Suspicious traffic on ports 5554, 9996 and 445
  • A file with several digits followed by _up.exe.
        For example 12345_up.exe


  • Solution  

    Visit Microsoft’s Sasser Worm Alert: What to do webpage. You will be able to download the Microsoft security update for this vulnerability, scan for and remove the worm, and find out more about protecting your computer.

    Alternatively, you may download the Sasser removal tool from Symantec. Remember to install the Microsoft security patch once the worm has been removed.

    Do update your Windows operating system regularly by installing the latest security patches from Microsoft. The security patches required by your operating system may be obtained by running Windows Update from the Start menu.

    Manual Removal   If you are unable to connect to the Internet or surf, do try the following instructions first:

    Windows XP
    1. Click START, select RUN and type MSCONFIG
    2. In MSCONFIG, click on the Startup tab and uncheck avserve and/or avserve2
    3. Restart Windows when prompted
    4. Enable the WinXP firewall before connecting to SingNet
      To enable the Windows XP firewall
      1. Click START and select CONTROL PANEL
      2. Open NETWORK CONNECTIONS
      3. Right-click the connection you want to protect
      4. Choose Properties from the dropdown menu
      5. Click the Advanced tab
      6. In the Advanced tab, select Protect My Computer And Network By Limiting Or Preventing Access To This Computer From The Internet

    Windows 2000
    1. Press CTRL-ALT-DEL and select Task Manager
    2. In Task Manager, click on the Processes tab
    3. Search the list for avserve and/or avserve2, and any process with several digits followed by _up.exe e.g. 12345_up. Select these processes as you find them and click End Process to terminate each
    4. Exit Task Manager

    Do contact your computer or antivirus vendor should you require further assistance in removing the worm from your computer.


     
    Internet Security
    > Spam
    > Spyware
    > Virus
    > Computer Security
    > Others
    > Disclaimer
    > Sign up SingNet Security Suite

    Technical Support
    Customer Service