Sasser
Worm :
How to deal with it Microsoft is actively
analyzing and providing guidance on a worm
identified as the W32.Sasser.worm,"which
is currently circulating on the Internet.
The worm and its variants exploit the Local
Security Authority Subsystem Service (LSASS)
vulnerability fixed in Microsoft Security
Update MS04-011 on April 13, 2004. Microsoft
is developing additional tools and information,
working closely with anti-virus partners
and aiding law enforcement in its investigation
in this criminal act. New information will
be posted to <http://www.microsoft.com/security>
as it becomes available. The worm attacks
Windows 2000 and Windows XP. Other versions
of Windows, including Windows Server 2003,
are not impacted by Sasser." Best protection:
Customers can protect against this worm
by installing Microsoft Security Bulletin
MS04-011 immediately. The MS04-011 security
bulletin is available at www.microsoft.com/technet/security/bulletin/ms04-011.mspx
<http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx>
Firewalls protect: Customers who have enabled
the Windows XP Firewall are protected from
the vector this worm attacks, which is TCP
Port 139. Most third party firewalls also
block this attack vector by default. How
to tell if you are infected: Customers who
are infected with the W32.Sasser.worm may
experience difficulty accessing the Internet.
Infected customers may also receive an LSASS.exe
error pop-up which may cause a reboot. How
to fix: Infected customers should follow
the manual clean-up steps detailed at <http://www.microsoft.com/security/incident/sasser.asp>
Customers who are still experiencing infection
symptoms may be infected with a different
threat and should update their anti-virus
signatures. More information on other current
threats is available at: Network Associates:
<http://vil.nai.com/> Symantec: <http://securityresponse.symantec.com/>
Trend Micro: <http://www.trendmicro.com/>
? Customers who still experience infection
symptoms after following the guidance or
who need assistance with the manual clean
up steps should contact the Microsoft PC
Safety Hotline at 1-866-PCSAFTEY. International
customers can receive support from their
local subsidiaries through <http://support.microsoft.com/international>
Microsoft is working with law enforcement
to forensically analyze the malicious code
and to identify the persons or entities
responsible for this criminal attack --
to ensure that they are brought to justice
and prosecuted to the fullest extent of
the law. As always, Microsoft continues
to recommend that all customers visit www.microsoft.com/protect
<http://www.microsoft.com/protect>
to take the three key steps to protect their
PCs. The three key steps are: 1. Use an
Internet Firewall on all PCs and Laptops:
An Internet firewall can help prevent outsiders
from getting to your computer through the
Internet. If you use Microsoft Windows XP,
enable the built-in firewall. 2. Update
Your Computer: Windows includes the automatic
updates feature (Windows Update) which can
automatically download the latest Microsoft
security updates. Windows 98 SE and Windows
ME can be updated from windowsupdate.microsoft.com.
3. Use Up-to-Date Antivirus Software: Installing,
configuring and maintaining antivirus protection
is absolutely essential. ? Frequently asked
questions about Sasser What does LSASS stand
for? Local Security Authority Subsystem
Service When was Microsoft made aware of
Sasser? Late Friday April 30th. How do you
know you are infected? If your computer
is infected with the W32.Sasser.worm, you
may see a dialog box with an LSASS.exe error.
Some customers whose computers have been
infected may not notice the presence of
the worm at all, while others who are not
infected may experience problems because
the worm is attempting to attack their computer.
Typical symptoms may include systems rebooting
every few minutes without user input. Windows
Server 2003 systems are not at risk from
this Worm. What does the worm do to the
users system? Our investigation is still
ongoing; however the worm appears to infect
a vulnerable system then immediately seeks
to infect other systems. We are continuing
our investigation to determine any further
actions the worm may seek to take. Is there
a fix available? Yes, install MS04-011.
Are there workarounds? Yes, there are workarounds
available including implementing firewall
best practices, standard default firewall
configurations and PYPC guidelines. Additional
information on workarounds can be located
at the following URL: <http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx>
Are there side effects of the workaround?
Side effects of the workaround can be found
at the following URL: <http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx>
CDROM and FDD cleaning CDROM Cleaning If
you are getting errors like "Please
insert a cd" while using the cdrom
If your computer gives you errors while
your using the cdrom , like in the middle
of a game the computer gives an error like
"Please insert the cd" you should
first try ejecting the cd and inserting
it again. If that does not remedy the problem,
try going to a local stationery or computer
store and purchasing a CD disk Cleaner kit,
costing around Rs.80/-. This will provide
you with a cleaning cd that you can insert
into your computer and it will clean the
lens. Please note that a cleaning process
may be required if you use "dusty or
scratched" CD media in your CD ROM.
Always keep your disks media covered in
a protective box/cover. CD CLEANING Why?
Dirty CDs can cause read errors and/or cause
CDs to not work at all. Procedure: Cleaning
CDs can be done with a CD cleaning kit however
can also be done with a normal clean cotton
cloth or shirt. When doing this with a clean
cotton cloth or shirt, wipe against the
tracks, starting from the middle of the
CD and wiping towards the outer side of
the CD. Never wipe with the tracks doing
so may put more scratches on the CD. It
is recommended when cleaning a CD that water
be used. However, if the substance on a
CD cannot be removed using water, pure alcohol
can also be used. FLOPPY DRIVE CLEANING
If the disk drive head becomes dirty, "data
errors" may occur. Accumulated dirt
can scratch the disk. Regular cleaning is
important to avoid dirt buildup. To clean
the disk drive head, use a commercially
available fluid-type cleaning disk for dual-sided
drives. Cleaning Procedure (1) Moisten the
cleaning disk with cleaning fluid. (2) Immediately
insert the cleaning disk into the disk drive
and execute a read operation. (Any type
of load operation is ok.) An error message
will appear. (3) After approximately 10
seconds, press the eject button, and remove
the cleaning disk. (4) For approximately
5 minutes, do not use the disk drive. (Using
the disk drive before the cleaning liquid
has dried may cause malfunctions.)