Today in BoomBlog, we are going to talk a little bit about computer's history. Especially we'll be talking about Sasser.
You are probably asking yourself what "Sasser" is, aren't you? Well, keep reading and you'll find out inmediately!
Sasser is a type of malware known as "computer worm". It first appeared on May of 2004. It affected around a million computers in the world and attacked every computer that used the operative systems of
Windows 2000, Windows Server 2003 and Windows XP and each computer that had installed on it LSASS (Local Security Authority Subsistence Service).
How did it work?
Sasser was programmed to execute 128 processes that analyzed an amount of random IP addresses in search of vulnerable systems. Then, it installed an FTP server for other infected computers to download it. Then, when it found a vulnerable computer, the worm opened a remote shell on the computer and made it to download a copy of the malware (named avserve.exe or avserve2.exe) in the Windows directory. Once the file was downloaded, the worm created a file called win.log (or win2.log) that recorded the amount of equipment that could be infected. It then created registry entries to be reset each time the computer restarted.
The virus run "Abort System Shutdown" to prevent the user or other viruses to restart the computer (or disable it).
In order to ro remove the Sasser worm, the best method is, first, protect the system by activating firewall. In Windows XP, go to
Start Menu> Settings> Control Panel> Network Connections.
Then click with the right mouse button on the Internet and Properties . Click the "Advanced" tab, then check the box "Protect my computer and network by limiting or preventing access to this computer from the Internet" and apply it by clicking OK.
Then you should upgrade the system, either by using Windows Update or by downloading and installing the patch that fits your operating system.
Finally, you can disinfect the system with a disinfection kit.
Here we have an image of the window that appeared when your computer was infected with this kind of worm:
That's all for today!