Select the product you need help with
A tool is available to remove the Sasser worm variantsArticle ID: 841720 - View products that this article applies to. NoticeThis tool is no longer available. It has been replaced by the Microsoft Windows Malicious Software Removal Tool. For additional information about the Malicious Software Removal Tool, click the following article number to view the article in the Microsoft Knowledge Base:890830
(http://support.microsoft.com/kb/890830/
)
The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Server 2003, Windows XP, or Windows 2000
On This PageSUMMARYMicrosoft has released a tool to help you remove the Sasser worm variants from your computer. If you are running Microsoft Windows 2000 Service Pack 2 (SP2) or later or a 32-bit version of Microsoft Windows XP, the Windows Update Web site and Automatic Updates will offer you version 2.0 of the Microsoft Sasser Worm Removal Tool to remove Sasser.A, Sasser.B, Sasser.C, and Sasser.D infections. Technical updatesVersion 4.0 of the Sasser Worm Removal Tool includes support for removing the Sasser.A, Sasser.B, Sasser.C, Sasser.D, and Sasser.E variants of the worm and adds support for removing the Sasser.F variant of the worm. Version 4.0 is available from the Microsoft Download Center.
SYMPTOMSAfter you install the 835732 (MS04-011) security update on a
computer that is already infected with the Sasser worm, the computer may
continue to generate network traffic on the affected Transmission Control
Protocol (TCP) ports to try to spread the worm infection to other vulnerable
computers. If your computer is infected with the Sasser worm, you may
experience one or more of the following symptoms:
For more information about the 835732 security update, visit the following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx Note Local Security Authority Subsystem Service (LSASS) provides an
interface for managing local security, domain authentication, and Active
Directory processes. LSASS handles authentication for the client and for the
server. It also contains features that are used to support Active Directory
utilities.
(http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx)
CAUSEThis behavior occurs because your computer is infected with
the Sasser worm. Together with using a firewall and installing the 835732
security update, you must also remove the Sasser worm from any infected
computers. A firewall and the 835732 security update prevent the Sasser worm
from infecting your computer. However, you must also take steps to remove any
infection that existed before you implemented these preventive measures.
For more information about how to determine whether your computer is infected with the Sasser worm, visit the following Microsoft Web sites:
RESOLUTION Microsoft has released a tool to remove the Sasser worm
variants from computers that are running one or more of the products that are
listed in the "Applies to" section. Important Microsoft also recommends that you use an Internet firewall and a current antivirus program, and that you keep both Windows and your programs up-to-date. For additional information about how to prevent viruses, and about how to recover from virus infections, click the following article number to view the article in the Microsoft Knowledge Base: 129972
(http://support.microsoft.com/kb/129972/
)
Computer viruses: description, prevention, and recovery
Download and setup informationIf your computer is infected with any one of the A-D variants of the Sasser worm, use Automatic Updates to download and install the Sasser Worm Removal Tool, or visit the following Windows Update Web site and install the KB841720 critical update.http://update.microsoft.com/ Release Date: May 4, 2004
(http://update.microsoft.com/)
For additional information about Automatic Updates, click the following article number to view the article in the Microsoft Knowledge Base: 294871 To deploy this update, IT administrators can use
Microsoft Software Update Services (SUS). For more information about SUS, visit
the following Microsoft Web site:
(http://support.microsoft.com/kb/294871/
)
Description of the Automatic Updates feature in Windows
http://technet.microsoft.com/en-us/wsus/bb466201.aspx Notes
(http://technet.microsoft.com/en-us/wsus/bb466201.aspx)
Release informationSasser Worm Removal ToolCollapse this table
Sasser worm variantsCollapse this table
PrerequisitesThe Sasser Worm Removal Tool has the following prerequisites:
827218 If these prerequisites are not met, the
installation will not work, and you will receive an error message. For more
information about the error message, view the following log file:
(http://support.microsoft.com/kb/827218/
)
How to determine whether your computer is running a 32-bit version or a 64-bit version of the Windows operating system
%Windir%\debug\sasscln.log Additionally, it is a good idea to install the 835732 (MS04-011)
security update before you run the Sasser Worm Removal Tool. Although version
4.0 of the removal tool will remove the worm from infected computers, it will
not prevent re-infection if your computer is still vulnerable. By installing
the 835732 security update before you run the removal tool, you can help
prevent re-infection by the worm.Restart requirementYou do not have to restart your computer after you install this tool.Usage informationNote Before you follow these steps, make sure that you have backed up all your important data.When you install the Sasser Worm Removal Tool version 4.0 and accept the end-user license agreement (EULA), the installation package extracts the Sasscln.exe file to a temporary directory, and then the removal tool runs. The removal tool checks your computer for the prerequisites that are listed in the "Prerequisites" section. If the prerequisites are met, the removal tool does the following:
Command-line switchesThe removal tool installer supports the following command-line switches:
197147 The removal tool supports the following command-line
switch:
(http://support.microsoft.com/kb/197147/
)
Command-line switches for IExpress software update packages
Removal informationThe Sasscln.exe file is automatically deleted from its temporary location after the removal tool runs. You can delete the tool's installer package after you install the removal tool.Note After you install the Sasser Worm Removal Tool (KB841720), it does not appear in the Installed programs list in the Add/Remove Programs tool in Control Panel. MORE INFORMATIONFrequently asked questions
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use
(http://go.microsoft.com/fwlink/?LinkId=151500)
for other considerations.PropertiesArticle ID: 841720 - Last Review: February 3, 2011 - Revision: 12.1
| Article Translations
|


Back to the top








