Sasser is a computer worm which can affect Windows 98, 2000 and XP based computers. It is also occasionally known as the Big One. As Sasser is a worm is spreads by itself without requiring user intervention, it spreads through an unsecured network port. This can be stopped easily by using a firewall which is properly configured. Downloading and installing the updates from Windows Update should also close the security hole. Microsoft released a patch closing the exploit 17 days before Sasser was first noticed.
The worm relies on the LSASS security vulnerability which was patched by Microsoft back in April 2004, if you install the windows update patches then you should be safe from this particular worm. Many security experts have suggested that worm creators reverse engineered the windows update so that they could learn about the unknown insecurity which left millions of computers which weren't updated insecure. If the computer was not updated then no protection from the worm was provided.
Sasser had some pretty important victims, including Delta Air Lines who had to cancel a number of trans Atlantic flights as a result of their computers becoming infected with the Sasser virus. The British Coastguard was also without their mapping system for a couple of hours.
Sasser was written by a 17 year old computer science student in Germany known as Sven Jaschan, he also admitted writing Netsky.AC which was a variant of the Netsky computer worm. Because Jaschan was under 18 at the time of writing the worm he was tried as a minor, the worm was actually released on his 18th birthday.
The easiest way to tell if your computer is infected is by looking for the existence of a file called win.log or win2.log on the root of the same drive as your operating system. You might also notice the service LSASS.exe closing as a result of some bad code, this start a countdown timer to switch the computer off, this can be stopped by going to: Start -> Run, and then entering "shutdown -a". This will cancel the shutdown command and you can continue doing whatever it is you were doing.
Sasser virus removal isn't as difficult as you might imagine, all you need to do is make sure that your anti virus software is completely up to date and functioning. Then you can run a scan to remove virus. Once you have eradicated the virus make sure that you install a full featured firewall to prevent your computer becoming infected by any other computer worms in the future.
The Sasser worm is less of a risk now, as it has been patched in all recent versions of windows. However you need to make sure that you download an antivirus program such as Micro Antivirus so that you can be protected in the future. This anti virus program has all the functions required to detect and remove viruses from your system, it also comes with regular updates to make sure that you detect every single virus.
|