Are These Sasser Worm Symptoms?

From: MAP (anonymous_at_discussions.microsoft.com)
Date: 05/06/04


Date: Thu, 6 May 2004 08:17:42 -0700


>-----Original Message-----
>I know what to do if I have the Sasser worm, and I also
have plans afoot
>to get a firewall in by the end of the week. I'm a home
user of XP, but
>I have XP Professional. My Internet connection is via a
DSL line, so I
>think (but I am not sure) that this means that I can get
something
>through my connection without knowing it, possibly even
when I'm not
>signed on to the Internet, and possibly even without the
computer being
>turned on.
>
>Anyway, here are some things that have happened to my
computer in the
>past week or so. Have any of you had any of these
problems, and if so,
>do you know what caused it?
>
>1. Norton Anti-Virus got corrupted to the point that the
virus checking
>was turned off. Plus LiveUpdate no longer works - I get
a message that
>says, "LU1848 Couldn't create callback object." I am
aware that this is
>a Microsoft help group, not a Symantec/Norton help
group. I have already
>found fixes for these on the Symantec site. I am only
posting this item
>to find out if others have had this problem, too.
>
>2. Windows Media Player got uninstalled. Fortunately, I
was able to get
>it back by running Windows Update and downloading it as
a suggested
>Windows XP addition.
>
>3. A left-side frame with Lycos in the name showed up on
a Google search
>results page. I was able to click in an "x" in a corner
to get rid of
>it. The next time I went to the desktop, I saw a new
icon to start up
>this Lycos item. I went into Add/Remove programs in the
Control Panel
>and found this item with a date of 5/5/04 (the day this
happened). I
>removed it, and so far it doesn't seem to have returned.
>
>4. I am getting an inordinate number of pop-up ads. I've
been remiss in
>installing a pop-up blocker because the number I got,
from such sites as
>www.snopes.com, www.imdb.com, and www.espn.com that rely
upon a
>reasonable number of these, was manageable. I'm getting
these at sites
>that would almost certainly not have pop-ups, including
ones run by the
>U.S. Government. While a "solution" to this is to get a
pop-up blocker,
>I want to treat the problem itself, not the symptoms.
Plus, some web
>sites I visit use the same technology as pop-ups to
display legitimate
>information, so I don't want to close myself out of
these.
>
>5. The past two days, as I've tried to go to Symantec's
site, a
>full-screen page to order a different anti-virus product
appears. I
>don't know if this is a spoof or a legitimate page. The
only way to get
>rid of this page that I have found so far is to do Ctl-
Alt-Del and then
>End Task for this displayed page (which does not shut
down Internet
>Explorer totally, and once that page is gone, I can see
Symatec's okay).
>
>Thanks for any comments anyone has regarding these.
>--
>Please note my correct email address:
>
>rslitman [at-sign] infionline [dot] net
>
>.
>
Sounds more like spy/adware except for the part about
norton being disabled,that may? be a sign of a virus to
know for sure update its virus definitions and run a scan
while in "safe" mode.
No you will not be able to get a virus/trojan or worm
while you are not connected to the internet or if your
system is "off".
While your wating to get a firewall turn on the one that
comes with XP or download zone alarm from
www.zonelabs.com
This is a free firewall.I have never used it but many
people swear that it is a good one.
To check for spyware use these tools.

 Spybot "Search and Destroy"
http://www.safer-networking.org/

Spywareblaster
http://www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/spywareguard.html

Ad-aware
http://www.lavasoft.de/

CWS Shedder,Hijackthis,BHO Demon
http://www.spywareinfo.com/~merijn/downloads.html
   
winpatrol
http://www.winpatrol.com/

CWShredder (Line 313) Home page lock (Line 63)
Hijack this (Line 116)
http://www.kellys-korner-xp.com/xp_tweaks.htm

http://www.spywareinfo.com/forums/

http://www.pestpatrol.com/PestInfo/

http://www.aumha.org/a/hjttutor.htm

The firewall should be your first priority!



Relevant Pages

  • Re: Firewall
    ... firewall that is compatible with AOL, or switch to a real ISP that is ... firewall and WinXP's Internet Connection Sharing feature. ... What You should Know about the Sasser Worm and its Variants ...
    (microsoft.public.windowsxp.security_admin)
  • Re: windowsxp
    ... What You Should Know About the Sasser Worm and Its Variants ... PSS Security Response Team Alert - New Worm Sasser ... Enable the Windows XP Internet Connection Firewall or a ... Disconnect the computer from the Internet. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: LSA Shell (Export Version) - System Shutdown
    ... Hi Nick. ... What You Should Know About the Sasser Worm and Its Variants ... Disconnect the computer from the Internet. ... Enable your firewall. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Pop-Ups
    ... You can disable the Messenger service, but that is unwise as a solution as ... protection from the Internet. ... see www.sygate.com for a free personal firewall. ... > I received an unsolicited pop-Up (I didn't even have ...
    (microsoft.public.security)
  • Re: lsass problem
    ... Probably you have the sasser worm. ... third-party firewall on the affected computer. ... Disconnect the computer from the Internet. ... Microsoft Security Bulletin MS04-011 ...
    (microsoft.public.windowsxp.help_and_support)

Loading