Home > Business > Business Headline > Report

How to stop the Sasser virus

Agencies | May 05, 2004 15:11 IST

The Sasser virus which infects computers running Microsoft's Windows operating system has led to the slowing down and at times the shutting down of Internet systems due to excess traffic.

Apart from Microsoft, various other antivirus companies---Like Symantec, Network Associates and Computer Associates have tools to remove and protect yourself from Sasser.

Most of them recommend the setting up of a firewall to ensure that worm does not reinfect your PC.

Based on some of these recommendations, here's how you can remove the virus and protect against it.

One, if you don't have a firewall, get one. Access either Microsoft or other anti-virus vendors on the Internet and run their anti-Sasser programmes.

Sasser slows and shuts down Internet connections by generating excess traffic, so if you are unable to access the internet long enough to run these programs or download the firewall, copy the program from an uninfected PC on to a disk and run it on the infected one.

If that can't be done, here's a manual way.

One, track and kill the worm. To do this:

# Press control-alt-delete once,

# Click on task manager

# Click on the processes tab

# Shut down all processes with the following names: avserve.exe; or 4 or 5 digits followed by _up.exe (e.g. 74354_up.exe).

# Exit task manager.

(If you're running Windows Me or XP, disable the System Restore feature to avoid  the computer from restoring the virus while backing up)

Two: Shut down your computer and disconnect Internet cables or wireless cards.

Three: Restart the computer in 'safe mode,' by pressing the  F8 key when the screen displays the 'starting Windows' text.

Four: Go to the Windows Explorer and delete the file AVSERVE.EXE from your WINDOWS directory (typically c:\windows or c:\winnt)

Five: Carefully edit the computer's 'registry' to wipe out the worm by

I. Click the 'start' button.

II. Click 'run.'

III. Type REGEDIT and press enter.

IV. Use the correct plus signs to get to this folder: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

V. In the right pane, delete the value: "avserve.exe"="%Windir%\avserve.exe"

VI. Exit registry editor by clicking on the x in the top right of the window. (Do this very, very carefully).

Finally, reboot the computer in default mode, connect to the Internet and run one of the tools from the Web sites listed earlier.

Don't forget to turn on System Restore if you've switched it off.


DISCLAIMER: While efforts have been made to ensure the accuracy of the information provided, rediff.com shall not be held responsible for any loss, harm or injury arising in any manner whatsoever caused to any person who uses the content provided at this site. Readers are advised to cross check the information and seek professional advice before taking any decision.


Article Tools
Email this article
Top emailed links
Print this article
Write us a letter
Discuss this article



















Copyright © 2004 rediff.com India Limited. All Rights Reserved.