Anglais minimum Requis
Removal Instructions
All Users :
Use the specified DAT files for detection and removal.
Alternatively, the following EXTRA.DAT packages are available.
EXTRA.DAT
SUPER EXTRA.DAT
Infected systems should install the Microsoft update to be protected from the exploit used by this worm. See:
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
If the system reboots before you are able to download and install the patch, the shutdown utility can abort a shutdown that is in progress ( counting down). This utility is part of Windows XP.
Click START, RUN
Type SHUTDOWN -A and hit ENTER
Additional Windows ME/XP removal considerations
Stinger
Stinger has been updated to assist in detecting and repairing this threat.
Manual Removal Instructions
To remove this virus " by hand", follow these steps:
Reboot the system into Safe Mode ( hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
Delete the file SKYNETAVE.EXE from your WINDOWS directory ( typically c:\windows or c:\winnt)
Edit the registry
Delete the " SKYNETAVE.EXE" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Reboot the system into Default Mode
Sniffer Customers
Filters have been developed that will look for Sasser traffic [Sniffer Distributed 4.1/4.2/4.3, Sniffer Portable 4.7/4.7.5, and Netasyst].
SnifferFilter - W32_SasserWorm.zip
McAfee Intrushield
This worm is detected in all Intrushield signauture sets 1.5.37.5, 1.8.27.2, 1.9.8.2 and later. In the IntruShield Alert Viewer, you would see the following alert when Sasser worm propagation is detected:
DCERPC: Microsoft Windows LSASS Buffer Overflow ( 0x47601c00)
Customers with in-line deployment should configure the sensor response of the above signature action to block in the policies.
McAfee System Compliance Profiler
Create a rule to match a registry key
Select HKEY_LOCAL_MACHINE from the drop-down box
In the field after the drop-down box, enter in the path Software\Microsoft\Windows\CurrentVersion\Run
For Value name, enter skynetave.exe
In the next drop-down box, select " Registry value does not exist"
McAfee Desktop Firewall
To prevent possibly remote access McAfee Desktop Firewall users can block incoming TCP port(s) 5554, 9995
McAfee Threatscan
ThreatScan users can detect the remote access component by running a Resource Discovery Task using the following settings:
Select TCP Port scan
Enter ports 5554,9995