Jump to content

Sasser Virus!


YT2095

Recommended Posts

Just so you know, my Virus Scan just found a Trojan.

It's not like I'd search through all my computer to see if I have one, then delete it. Any AV program can search a lot faster than you can. So at least you can use one as a back-up. Would you search through every part of a download to make sure it doesn't contain a virus? I don't think so.

Link to comment
Share on other sites

  • Replies 71
  • Created
  • Last Reply

Top Posters In This Topic

That sounds like an awful lot of work to me, and I don't believe you can identify an infection and locate the affected files without reference to external documentation.

 

there's nothing wrong being a bit 'extra' geeky - provided that it doesn't adversely affect one's life quality. ;)

so if someone and not just in fafs case, has a more or less unorthodox methods of doing things, then after a certain point in time it ceases to be a matter of skill, but one of pride and bragging rights

Link to comment
Share on other sites

The person who set up and programed the Sasser virus has now been track down. He goes to a school in Germany and is going to face trial in a few months time.

 

Clever kid to have though up a program that has crashed so many computer systems!

Link to comment
Share on other sites

The affected files for the vast majority of what infects peoples computers these days are single executables that are always listed in some startup location. Just gotta find the suspicious looking entries.

Link to comment
Share on other sites

The affected files for the vast majority of what infects peoples computers these days are single executables that are always listed in some startup location. Just gotta find the suspicious looking entries.

 

It's when you get the ones that like to screw the registry over a bit that you're going to have a problem.

Link to comment
Share on other sites

It's when you get the ones that like to screw the registry over a bit that you're going to have a problem.

Or, like I mentioned earlier in the thread, a forced-writer.

 

Or a boot sector infection. Good luck with that one.

Link to comment
Share on other sites

Once those programs start running you're really screwed no matter what approach you use...

Yes, that's precisely why I use Sophos. With the Intercheck client running, they can't do anything.

 

And if you're running programs from an untrusted source you deserve whatever happens...

Agreed.

Link to comment
Share on other sites

  • 1 month later...

So for those of us that use A/V, which one do you use?

 

I read all 4 pages, & I've hard Norton tossed around quite a bit.

 

Sayo: you talked about that sophos, I'm intrigued; tell me more :) From what I've read on the site you gave me, they provide security solutions for business/corporations. How do you use it?

 

How does McAfee rate against Norton?

I always thought [back in the day] that McAfee ruled the market. Now, all my friends use Norton [& apparently alot of SFNers too].

Link to comment
Share on other sites

McAffee is more for network solutions now.

 

Sophos has one installer with a choice of two deployment options: one for central deployment on a network, and one for installing to a single workstation (i.e. - your PC).

 

It runs a thing called "intercheck client" from your system tray, essentially a very resource-light mini scanner, which checks files as they are accessed. You can also launch the full "Sophos Antivirus" application and configure immediate or scheduled jobs.

 

It gives you plenty of options for configuring the thoroughness of scans, type of response to infections etc.

 

When you download Sophos, you also need to download any IDEs released since the client was released, then subscribe to their Virus Notification mailing list. They send you links to IDE files for new virus (typically before they are spotted "in the wild"), which you simply save to the Sophos installation directory. The next time the intercheck client starts it will register and use them.

 

If you have the network installation running, you can deploy new IDEs centrally. Also you can use tools that Sophos provide to auto-update.

 

The only disadvantage with Sophos is that every 4 months the client is upgraded and new IDEs will not work with the last version. That means you need to download it 3 times a year (unless you buy the license of course), but it's worth the minor hassle for a free industry-leading application.

Link to comment
Share on other sites

  • 1 month later...

Ed yeah, that`s what it said to do on the MS website also, the only prob was getting to that part to read it before the puter shutdown LOL, that took me about 3 attempts, but each time was hindered by the fact that I had to get the owner to type in their password each shutdown :(

 

it was a real PITA!

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.