W32.Nosferatu....
Nov. 15th, 2004 02:54 amSomeone's finally gone and done it... they've made Sasser immortal! Poor luser called in (sounding like he'd just had a fifth of scotch and smoked a pack, then washed it down with some broken glass), and... in the past week or two, we've debugged and reformatted his hard drive, full reformats, mind you, the ones we get to leave for lunch, then come back to finish the call for, at least twice. Sasser is still on his system (not to mention Norton and all his drivers). I consult my immediate higher-up, who shows me the bad mamma-jammin' BIOS level debug script. After it's done, we literally have to remind BIOS that the hard drive is even frelling there. then I start his format. I'm with another customer when callback time rolls around, but another tech at our location gets the call, and, guess what! Sasser is STILL on his machine! lsass.exe errors and everything. I think I owe the other tech lunch now. Or my firstborn, depending on who calls this guy back tomorrow for round whatever with the Worm That Would Not Die.
So, basically... has anyone else encountered this? Are we all just smoking crack at TCWMNBN? Is his hard drive too frelled up to erase data? Do I just need to get more sleep?
So, basically... has anyone else encountered this? Are we all just smoking crack at TCWMNBN? Is his hard drive too frelled up to erase data? Do I just need to get more sleep?
no subject
Date: 2004-11-15 01:13 am (UTC)no subject
Date: 2004-11-15 01:39 am (UTC)Also are you really obliterating the data ont he disk, or just formatting. You could try formatting, writing over the disk, then formatting again, then re-installing to make sure the data is gone not just hte filesystem.
no subject
Date: 2004-11-15 01:57 am (UTC)no subject
Date: 2004-11-15 01:59 am (UTC)Sasser and Blaster are both notorious for lurking on ISP proxy servers and places like that...
IV
no subject
Date: 2004-11-15 02:02 am (UTC)no subject
Date: 2004-11-15 02:23 am (UTC)IV
no subject
Date: 2004-11-15 02:25 am (UTC)no subject
Date: 2004-11-15 05:13 am (UTC)no subject
Date: 2004-11-15 04:25 am (UTC)No, only CoolWebSearch is immortal.
Date: 2004-11-15 04:47 am (UTC)The only solution is to make sure the network cable is disconnected until the machine is finished booting unti you get SP2 on there.
Re: No, only CoolWebSearch is immortal.
Date: 2004-11-15 06:00 am (UTC)We DO NOT mention that spyware's name!!!
Actually, It's more like Gator. I *still* find that on machines, even though the company has changed it's name at least once, and the fact that the program is ancient.
I've been extremely lucky at work; I've only run across a few machines that has those worms on them, and they were all systems with outdated A/V software. a quick patch (or 5) and the problem was gone.
At one point, Microsoft offered a free CD which contained all the security updates for 98 and 98se and possibly ME as well, but apparently too many people took advantages of a free CD. they don't offer it anymore ::sigh:: That was the second CD I stuck in the machien after re-loading it. (At least for 98. I also have XP SP2 on a CD as well)
no subject
Date: 2004-11-15 07:11 am (UTC)Gateway makes a great little utility (the only thing good that came from that company) called gwscan.
http://pacomputing.org/downloads/gwscan.exe
If that doesn't work, a sledgehammer will.
no subject
Date: 2004-11-15 08:11 am (UTC)no subject
Date: 2005-08-23 06:36 pm (UTC)