Avast WEBforum

Other => Viruses and worms => Topic started by: Stephan123 on May 01, 2004, 05:45:22 PM

Title: Virus.Sasser a
Post by: Stephan123 on May 01, 2004, 05:45:22 PM
have Alwil this virus already.And are we protected against this virus ???
Title: Re:Virus.Sasser a
Post by: pk on May 01, 2004, 05:54:28 PM
After latest virus database update in the morning (418-6), avast is able to detect this virus. It uses a lsass vulnerability - technical details (http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html) + windows patch (http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx).
Title: Re:Virus.Sasser a
Post by: Pavel Baudis on May 01, 2004, 10:15:31 PM
Actually - there is a new Sasser variant - Sasser-B tonight. The update is already out, so feel free to update  ;) .

However the best protection against this kind of viruses/trojans is to install all the Windows critical patches - see the link above or use "Windows Update" feature!

Pavel
Title: Re:Virus.Sasser a
Post by: Sgt.Schumann on May 01, 2004, 11:18:56 PM
Thank you for the info about Sasser.B !!

What is the difference between the two variants?
Title: Re:Virus.Sasser a
Post by: fred1479 on May 01, 2004, 11:45:03 PM
Hello !

My computer is infected by the win32: sasser-B ....
It infects many files...And I get bored !!! :'(

Avast! detects it but it says the worm is somewhere
" C:\WINDOWS\avserve2.exe"

but no action is available. The file is unfundable . I can't delete it, rename, repare or put it in "quarantaine".  sorry for my english, I'm french.

If you have solutions...
bye :P
Title: Re:Virus.Sasser a
Post by: Pavel Baudis on May 02, 2004, 10:13:17 AM
Try to terminate the virus process first:


avserve.exe
any process with a name consisting of 4 or 5 digits followed by _up.exe (eg 73461_up.exe).
Then, you will be able to delete the files detected by avast! as infected.

Hope this helps

Pavel
Title: Re:Virus.Sasser a
Post by: Lars-Erik on May 05, 2004, 05:16:38 PM
Try to terminate the virus process first:

Why can't you make avast! terminate processes bound to infected executables so that avast! can delete them automaticly (a "kill process and delete file" button) ?

It's a bit like the locked files that can't be delted where I earlier suggested a "unlock and delete file" button ?
Title: Re:Virus.Sasser a
Post by: Pavel Baudis on May 05, 2004, 05:41:17 PM
Why can't you make avast! terminate processes bound to infected executables so that avast! can delete them automaticly (a "kill process and delete file" button) ?

This is of course done by avast! Cleaner (both standalone and embedded in the VPS file versions). But in the moment of my answer the cleaner was not able to handle Sassers - it has been released later.

Hope this helps
Pavel
Title: Re:Virus.Sasser a
Post by: Lars-Erik on May 05, 2004, 05:50:05 PM
This is of course done by avast! Cleaner (both standalone

Why not include this in the on-access scanner ?
It's kind annoying when you press "Clean" or "Delete" and
only get a "Unable to access file" or something.

If it's possible in the cleaner, why not in the on-access scanner ?
Title: Re:Virus.Sasser a
Post by: Pavel Baudis on May 05, 2004, 05:54:52 PM
If it's possible in the cleaner, why not in the on-access scanner ?

Cleaner knows exactly what it is trying to stop - and believe me, sometimes it is really very difficult to do this. Some viruses have different mechanisms how to stay active in memory, how to reload themselves and how to fight back. I think doing such things in general could be very dangerous - the boot scan is much better and safer for this purpose!

Title: Re:Virus.Sasser a
Post by: igor on May 06, 2004, 10:09:06 AM
Yes, just as Pavel says - it's not so simple. In general, you cannot just "terminate processes bound to infected executables". The virus may be running on other processes' memory area (either it infected their executable file, or it hooked their process during the runtime) - so with "generic" methods you could easily kill important system processes (and crash the system, of course).
Or, the virus may be loaded as a shared DLL into all the running processes...  so there actually is "no" virus process to terminate.
Title: Re:Virus.Sasser a
Post by: Lars-Erik on May 06, 2004, 11:59:52 AM
But at least you could do what the "Cleaner" does ?
I only suggest including the same solutions as there