Asultan
06-24-2004, 07:43 AM
<center>
فايروس شبيه بلاستر جديد !!W32/Sasser.worm
السلام عليكم
لمن تظهر لك نافذه هذا الفايروس الجديد تطالبك بايقاف تشغيل الجهاز بوقت محدد اعمل الاتي
اذهب الى start
ثم run
واكتب الامر SHUTDOWN -A
حتي يعطل عمل الفايروس مؤقتا
ثم حمل الباتش الخاص بالويندوز لديك
اكس بي عربي
http://download.microsoft.com/downl...732-x86-ARA.EXE
اكس بي انجليزي
http://download.microsoft.com/downl...732-x86-ENU.EXE
وندوز 2000
http://download.microsoft.com/downl...732-x86-ENU.EXE
للمزيد من المعلومات
http://www.microsoft.com/technet/se...n/MS04-011.mspx
----------
معلومات اكثر عن الفايروس
The virus copies itself to the Windows directory as avserve.exe and creates a registry run key to load itself at startup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "avserve.exe" = C:\WINDOWS\avserve.exe
As the worm scans random ip addresses it listens on successive TCP ports starting at 1068. It also acts as an FTP server on TCP port 5554, and creates a remote shell on TCP port 9996.
A file named win.log is created on the root of the C: drive. This file contains the IP address of the localhost.
Copies of the worm are created in the Windows System directory as #_up.exe.
Examples
c:\WINDOWS\system32\11583_up.exe
c:\WINDOWS\system32\16913_up.exe
c:\WINDOWS\system32\29739_up.exe
Method of Infection
This worm spreads by exploiting a recent Microsoft vulnerability, spreading from machine to machine with no user intervention required.
This worm scans random IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a remote shell on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and executes it. This FTP script instructs the target victim to download and execute the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host is accepts this FTP traffic on TCP port 5554.
The worm spawns multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets. The destination port is TCP 445
Removal Instructions
All Users :
Use the specified DAT files for detection and removal.
Alternatively, the following EXTRA.DAT packages are available.
EXTRA.DAT
SUPER EXTRA.DAT
Infected systems should install the Microsoft update to be protected from the exploit used by this worm. See:
http://www.microsoft.com/technet/se...n/MS04-011.mspx
Additional Windows ME/XP removal considerations
Stinger
Stinger has been updated to assist in detecting and repairing this threat.
Manual Removal Instructions
To remove this virus "by hand", follow these steps:
Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
Delete the file AVSERVE.EXE from your WINDOWS directory (typically c:\windows or c:\winnt)
Edit the registry
Delete the "avserve" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Reboot the system into Default Mode
وتحياتي لكم
:LL:
فايروس شبيه بلاستر جديد !!W32/Sasser.worm
السلام عليكم
لمن تظهر لك نافذه هذا الفايروس الجديد تطالبك بايقاف تشغيل الجهاز بوقت محدد اعمل الاتي
اذهب الى start
ثم run
واكتب الامر SHUTDOWN -A
حتي يعطل عمل الفايروس مؤقتا
ثم حمل الباتش الخاص بالويندوز لديك
اكس بي عربي
http://download.microsoft.com/downl...732-x86-ARA.EXE
اكس بي انجليزي
http://download.microsoft.com/downl...732-x86-ENU.EXE
وندوز 2000
http://download.microsoft.com/downl...732-x86-ENU.EXE
للمزيد من المعلومات
http://www.microsoft.com/technet/se...n/MS04-011.mspx
----------
معلومات اكثر عن الفايروس
The virus copies itself to the Windows directory as avserve.exe and creates a registry run key to load itself at startup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "avserve.exe" = C:\WINDOWS\avserve.exe
As the worm scans random ip addresses it listens on successive TCP ports starting at 1068. It also acts as an FTP server on TCP port 5554, and creates a remote shell on TCP port 9996.
A file named win.log is created on the root of the C: drive. This file contains the IP address of the localhost.
Copies of the worm are created in the Windows System directory as #_up.exe.
Examples
c:\WINDOWS\system32\11583_up.exe
c:\WINDOWS\system32\16913_up.exe
c:\WINDOWS\system32\29739_up.exe
Method of Infection
This worm spreads by exploiting a recent Microsoft vulnerability, spreading from machine to machine with no user intervention required.
This worm scans random IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a remote shell on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and executes it. This FTP script instructs the target victim to download and execute the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host is accepts this FTP traffic on TCP port 5554.
The worm spawns multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets. The destination port is TCP 445
Removal Instructions
All Users :
Use the specified DAT files for detection and removal.
Alternatively, the following EXTRA.DAT packages are available.
EXTRA.DAT
SUPER EXTRA.DAT
Infected systems should install the Microsoft update to be protected from the exploit used by this worm. See:
http://www.microsoft.com/technet/se...n/MS04-011.mspx
Additional Windows ME/XP removal considerations
Stinger
Stinger has been updated to assist in detecting and repairing this threat.
Manual Removal Instructions
To remove this virus "by hand", follow these steps:
Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
Delete the file AVSERVE.EXE from your WINDOWS directory (typically c:\windows or c:\winnt)
Edit the registry
Delete the "avserve" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Reboot the system into Default Mode
وتحياتي لكم
:LL: