Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Possible New Sasser Variant |
|---|---|
| Date: | Wed, 23 Mar 2005 23:05:18 +0000 |
I'm not too sure about your sasser like symptoms, though if it's anything like the users I have worked with, he might have an unpatched machine. Recently however, working in a school, I have encountered an outbreak of a virus known as Sumom.A which will do what you say and kill task manager and other things. I find that IF lsass.exe is killed by any means, yes, you will have that shutdown message. This apparently uses MSN messenger to spread with unpatched machines. I hope this link helps you track down the cause: http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=42017 If you are continually getting shutdown problems, I would suggest grabbing the latest virus updates via another computer and coping them to a USB removable device and putting them in your problem computer and copying them off, then booting to safe mode to install the updates and do a scan. Good Luck with it! Cheers -Edwin Quoting Syklops <syklops@duicon.com>:
Hi Guys, I work in Technical support for BT Yahoo Broadband and had a call from a = guy who appeared to have the sasser, the system was shutting down when = trying to access websites, and I attempted to fix the problem using = CTRL+ALT+DEL and kill the lsasss process, however, when I do that, Task = Manager does not appear. I get an egg-timer for about a second and it = disappears. A quick google did not find me mention of a variant of = sasser which killer Task Manager.=20 Have I found a new variant, or is this already known? Cheers -A-
---------------------------------------------------------------- This message was sent using IMP, the Internet Messaging Program.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Possible New Sasser Variant, Mark C Roper |
|---|---|
| Next by Date: | Re:Possible New Sasser Variant, syklops |
| Previous by Thread: | Re: Possible New Sasser Variant, Mark C Roper |
| Next by Thread: | Re: Possible New Sasser Variant, Nick FitzGerald |
| Indexes: | [Date] [Thread] [Top] [All Lists] |