How can a newly formatted and reinstalled windows got worm so quickly?

J

Jane

How can a newly formatted and reinstalled windows xp get
virus or worm so quickly? I reinstalled windows xp on my
niece's computer, then set up her e-mail program. After
only a couple of minutes online, without even opening her
e-mail program, it shut itself down. We discovered the
sasser worm. How could this have happened so quickly? She
was going straight to a web page to download her anti-
virus program and had only been online a couple of
minutes. I'd appreciate any info.
Jane
 
G

Guest

The one thing that would come to mind, is she didn't update her security bulletins offered by Microsoft that adresses these vuneralbilities in XP. Do Windows Update as soon as possible.
 
R

RA

When you install XP you must enable the built in firewall before you ever go
on line. Then you go online and before you do anything else, you must get
SP1 and all the hotfixes. There is lots of info on the web about Sasser. Use
google to search for it.
 
B

Bruce Chambers

Greetings --

You've apparently contracted the latest worm, W32.Sasser.Worm,
specifically designed to attack people who do not update their
computers promptly and who do not practice "safe hex." In other
words, like Blaster, this worm was developed and distributed _after_ a
patch for the vulnerability was announced and made publicly available.
Further, and also like Blaster, this worm could not affect any
computer whose user had taken the basic precaution of using a properly
configured firewall. It only takes a few milliseconds of exposure.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next Shutdown countdown begins. This will abort the shut down. Also,
make sure you've enabled a firewall before starting, to preclude any
more intrusions while getting the updates/patches/tools.

What You should Know about the Sasser Worm and its Variants
http://www.microsoft.com/security/incident/sasser.asp

Microsoft Security Bulletin MS04-011
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

W32.Sasser.Worm
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html

A tool is available to remove the Sasser worm variants
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

W32.Sasser.Worm Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/


Bruce Chambers
--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. - RAH
 
N

NoNoBadDog!

Congratulations!



Your system is infected with the much publicized Sasser worm. You have
allowed
yourself to become infected because of ALL of the following;


1. You have not updated your version of Windows.

2. You are not using an UP TO DATE antivirus program.

3. You connected to the internet without a firewall on your computer.

Until you correct ALL of the above situations, you will remain vulnerable to
infection not only by SASSER, but also by the thousands of other worms,
viruses, trojans, keyloggers, spyware, malware, etc.

Because you do not practice even the most basic level of computer security,
you are not only a threat to yourself but to the entire internet community.
When your machine is infected, it looks for other machines, owned by persons
like yourself who have poor computer security practices, to infect.

First, disconnect from the network.


When the shutdown message appears, go START > Run and type in "shutdown -a"
(without the quotes), and hit the enter key.

Download the Windows critical update and the SASSER removal tool.here are
the

links..



Security Update:



http://www.Microsoft.com/downloads/...9E-DA3F-43B9-A4F1-AF243B6168F3&displaylang=en





and the SASSER removal Tool:



http://www.microsoft.com/downloads/...7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en


After rebooting, go to the website of the company that makes your antivirus
program and download all the updates that are available. If your antivirus
has expired, you must
purchase a new one.
Third, go to www.zonealarm.com and download the FREE firewall.
Keep your version of Windows updated. Always install any critical patches
that are posted to the Microsoft update website.

Keep you antivirus program up to date. New virus detection signatures are
released nearly on a daily basis, so this is something you should do every
day. Not once a month, or "when I have time", or "when I remember".

Once you have done these things, you will find your internet experience to
be much safer and happier.


Bobby
 
G

Geri

I reinstalled XP and tried to install SP1 but that's when
my problems started. I have 47 "necessary" updates
including SP1 waiting to be installed but there are no
dates so I can't tell which I should install first, but I
assume SP1 is the most important. However, when I install
it I begin to have shut down problems and almost non-stop
errors. Further, SP1 is one of the reasons I had to
reinstall, or at least that's my suspician.

So, what am I doing wrong? Right now I'm trying to move
all of my important files to my other hard drive or to
the other computer I'm networked to, so I can do a
complete reformat, but then what happens to the PC that's
networked to my older computer, which is the "master"?
Will I mess up the network settings?

This is driving me nuts. I try to do what I'm supposed to
do but I don't have live-in tech support, which I
apparently need. It's tough when you're a complete novice
who has to bumble along and hope that I'm doing the right
thing.
Geri
 
A

Alex Nichol

Jane said:
How can a newly formatted and reinstalled windows xp get
virus or worm so quickly? I reinstalled windows xp on my
niece's computer, then set up her e-mail program. After
only a couple of minutes online, without even opening her
e-mail program, it shut itself down.

If you do not implement the firewall before ever going on line even for
a moment you are likely to be hit by a packet trying to install Blast or
Sasser in a minute or two . You need to go to Network Connections,
right click the drive and take Properties, to check it on the Advanced
page before you *ever* go on line. And preferably have the patches
ready on disk to install first too.
 
K

Ken Blake, MVP

In
Jane said:
How can a newly formatted and reinstalled windows xp get
virus or worm so quickly? I reinstalled windows xp on my
niece's computer, then set up her e-mail program. After
only a couple of minutes online, without even opening her
e-mail program, it shut itself down. We discovered the
sasser worm. How could this have happened so quickly? She
was going straight to a web page to download her anti-
virus program and had only been online a couple of
minutes. I'd appreciate any info.


By going online without a firewall and by not downloading and
installing Microsoft critical updates.

It can take seconds to get infected with Sasser and no E-mail is
necessary.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top