Sasser worm trouble. A friend's WinXP system was compromised, I was asked to disinfect it, and it's not behaving by the rules! [more inside]
OK, the sequence of events:
- She reports random booting, weird messages, etc. She's running GRISoft's antivirus, which reports that it's found Sasser.B, but is unable to remove it.
- The hosts file has been corrupted to stop me from getting to any antivirus sites, so I fix that, delete several copies of avserve2 from the task list, go to the Microsoft site and download and install the latest updates, then download and run their sasser worm removal utility. The utility says that no sasser worm was found.
- I go to Norton's site, get
their sasser removal utilty, and run it.
It reports that there's no sasser worm.
- I find a technical description of the worm (including the registry keys it adds/modifies), and delete them. Can't find anything else suspicious in the "Run" registry categories.
At this point, here are the symptoms I'm getting:
1) At boot, a message that the data at address '00000004'x could not be read. This is from the GRISoft code. Click OK, and everything seems fine.
2) Also at boot, the hosts file is again modified to add microsoft.com and all of the antivirus sites.
3) GRISoft reports that no viruses are found
Can anybody think of what I might try next? I'm lost.
posted by Dean_Paxton at 1:53 PM on May 3, 2004