Fixing Sasser
From JhuWiki
Contents |
[edit] Instructions for Windows
- Download the patch from Microsoft
- Download this and run it as fast as you can: the worm removal tool.
- Download this and run it as fast as you can, too: a worm removal tool.
- Let it run all the way through.
[edit] Reboot and relax.
- While you're relaxing, consider how to avoid this in the future:
- Know that only Windows users have this problem.
- While using Windows, be SURE to use Microsoft Windows Update frequently. Also, keep your Anti-Virus definitions updated and run a virus check every weekend.
[edit] Contact information
If you need help with this, you can email me at asheesh@jhu.edu. Use sparingly. ;)
[edit] Technical notes
- The F-secure removal tool seems faster to act: http://www.f-secure.com/v-descs/sasser.shtml , but does not cover the latest variant. So, I have recommended using one fast-acting fixer tool and one complete fixer tool. This should cover everything.
- The worm's variants are described in links from http://sarc.com/avcenter/venc/data/w32.sasser.removal.tool.html
- It'd be nice if people patched or ditched their Windows systems, but I'm biased.

