Home
How to remove the Sasser virus.


(*This will also work with "Skynet, MSBlaster, _up.exe, and others.)


To Download Stinger and remove the virus. You may need to stop the Virus process first.
(You do not need to download Stinger or stop the virus if you were sent the newest software CD in the mail. Skip to step 2, Turn off system restore.)

Step 1.) How to stop the virus
Hit "Control, Alt and Delete" at the same time". This will bring up the "Task Manager" screen.
(Then if needed, click on the processes tab. This is for Windows XP users.)

Look for any process named
"avserve2.exe"
Or one ending in _up, for example; "7845_up.exe"
Or one called skynet.exe
Highlight and click on end task.
This will temporarily stop the virus.



Next you will need to turn off system restore.
Step 2.)How to turn off system restore.
Single right click on the My Computer Icon.
From the pop up menu, left click on properties.
OR
Go to the Control Panel and double click on the system icon.

In the System Properties Window, Select the System Restore Tab at the top.
Place a check mark in the box; "Turn off system Restore".
Click apply or OK.



Next you will need to download Stinger.
(You do not need to download Stinger if you were sent the newest software CD in the mail. Skip to step 4, Run Stinger.)
Step 3.) How to Download Stinger
The current Version of Stinger can be downloaded and saved to your desktop from here.
http://vil.nai.com/vil/stinger/
(*Stinger is usualy named stinger06192004.exe, with the numbers representing the date it was created.)
From the download box click save to disk. Not Run or Open.
At the top of the "save dialog" box, choose desktop from the drop down menu.
Then click on "save, open or ok" to save the file.
Time for the download is approx. 5 minutes for a modem.
After the file is saved, you will have a new stinger icon, located on the desktop.



Next you will need to run Stinger.
Step 4.) How to Run Stinger
Double click the Stinger Icon located on your desktop (from step 3) and click the scan button.
Or
If running Stinger from a cd.
Insert the CD
The Cd Welcome screen should start up.
(If the cd does not start. Double click on the My computer icon. Then double click the uswa icon.)
On the welcome screen, click on the button "Exit this Screen".
In the new window, go up to the menu and click on antivirus.
Select the newest Stinger version listed and click.
Click the scan button to start stinger.
Scans will take from 15 to 30 minutes depending on your computer.



You should now check that your installed Norton/Symantec AntiVirus is current.
Step 5.) Check your Antivirus Version.
Go to Start, Programs, Symantec Client Security, and Antivirus Client.
The Virus Definition File Version date is listed on the bottom right.
The Version Date should be no more than 7 days old.



Last, you need to Update Norton AntiVirus to latest version
Step 6.) How to Update Norton AntiVirus
There are 4 methods to update Norton/Symantec antivirus.

Method 1.) The live update button.
Go to Start, Programs, Symantec Client Security, and Antivirus Client.
The Live Update button is located on the bottom right.
(If you are unable to update this way;
Fixs for this problem are available on the cd.
Read the help file "Norton Unable to Update" for more information.
For now, update from another method.)


Method 2.) How to run Norton update from the CD.
Insert the CD
The Cd Welcome screen should start up.
(If the cd does not start. Double click on the My computer icon. Then double click the uswa icon.)
On the welcome screen, click on the button "Exit this Screen".
In the new window, go up to the menu and click on antivirus.
Select the newest Norton update version listed and click.
This will complete the update process.

Method 3.) Manually download the updates.
Go to this website
http://securityresponse.symantec.com/avcenter/defs.download.html
and click on the download button.
(*Links may vary, follow links for DATS and look for a grey download button.)
A new web page will open, click on the link under FILENAME.
The link will be similar to 20040414-019-i32.exe
(*The numbers represent the date created.)
Click on the filename to start the download dialog box.
From the download dialog box, choose save this program to disk. Not Run or Open.
At the top of the "save dialog" box, choose desktop from the drop down menu.
Save it to your Desktop (not a floppy)
(If already exists, overwrite the previous version with this new version.)

Then click on "save, open or ok" to save the file.
Time for the download is approx. 20 minutes for a modem.
After the file is saved, you will have a new icon, located on the desktop.
Choose to open/run the file
Or
Click on the new icon, located on your desktop.
This will complete the update process.

Method 4.) Automatic Updates.
This feature works on a few computers.