Date: 2004-05-15 09:09 am (UTC)
If it IS Sasser, here's what to do. (This is straight from my playbook.)

Cold-boot the machine. Open up task manager via ctrl-alt-del, ctrl-shift-esc, or by typing taskmgr into a Run box. Look for the following processes. One or more may be present:

avserve.exe
avserve2.exe
hkey.exe
lsasss.exe (NOTE THE EXTRA 's'. lsass.exe is a valid Windows system file!)
skynet.exe
skynetave.exe

And anything taking up large quantities of CPU time. (Note that if there are two or more processes battling for CPU, end the one that looks the most suspicious. Sometimes valid system processes will fight over something with, say, antivirus software, and when you kill one the other finishes what it needed and behaves.)

Once the processes are killed, go get the patch and removal tool from Microsoft Download Center. Specifically, you want Security Update for Windows XP (KB835732) and Sasser (A-F) Worm Removal Tool (KB841720). Install the patch, run the removal tool, and you're set. If necessary, download the files on a different computer and burn them to CD.

If a Windows NT Authority shutdown kicks in, telling you you have 60 seconds and the computer will shut down, go to Run in the start menu and type shutdown -a. That'll abort a shutdown. Repeat as necessary.

Good luck, dollie.
This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

Profile

cabbitzilla: (Default)
cabbitzilla

June 2020

S M T W T F S
  123456
78910111213
14151617181920
21222324252627
28 2930    

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 19th, 2026 06:03 am
Powered by Dreamwidth Studios