Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Sasser problem - a countdown of zero seconds...

Thread Tools
 
Search this Thread
 
Old 04 May 2004, 10:13 PM
  #1  
Jerome
Scooby Regular
Thread Starter
 
Jerome's Avatar
 
Join Date: Sep 2000
Posts: 4,460
Likes: 0
Received 0 Likes on 0 Posts
Question Sasser problem - a countdown of zero seconds...

How do you get into a laptop that has been hit by the Sasser virus which, upon logging on, immediately reboots?

When it first got hit the countdown was 5 minutes. The user (the sister of my boss) ignored each countdown and reboot until the up time was less than 30 seconds(!). By the time my boss got to look at it, it was too late - he didn't have enough time to fix it. Now the countdown time is zero seconds.

One of the support guys at work has looked at the machine and can't even get in via safe mode and/or via the admin account. Booting via a floppy or CD doesn't work either.

Other than wiping the hard drive, is there a way of fixing this machine?

The machine is running XP.
Old 04 May 2004, 10:17 PM
  #2  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Remotely edit the registry to remove the keys from \Run?
Old 04 May 2004, 10:33 PM
  #3  
suba
Scooby Regular
 
suba's Avatar
 
Join Date: Mar 2000
Posts: 2,462
Likes: 0
Received 0 Likes on 0 Posts
Default

and the reg key to delete is...

HKLM\software\microsoft\windows\currentversion\run

on the right pane, there should be something "uncheck.... %..." sorry i cant remember the exact line but it's something like in the quote.
Old 05 May 2004, 03:27 PM
  #4  
Jerome
Scooby Regular
Thread Starter
 
Jerome's Avatar
 
Join Date: Sep 2000
Posts: 4,460
Likes: 0
Received 0 Likes on 0 Posts
Default

How do you edit the registry if you can't get into the system?

Can you edit the registry from BIOS?
Old 05 May 2004, 03:30 PM
  #5  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

From another PC over the network (assuming you have a network and a second PC!)

That's presuming the shut down countdown starts when you log on, not as the system boots.
Old 05 May 2004, 03:35 PM
  #6  
Jerome
Scooby Regular
Thread Starter
 
Jerome's Avatar
 
Join Date: Sep 2000
Posts: 4,460
Likes: 0
Received 0 Likes on 0 Posts
Default

The shutdown is immediate - the moment you hit return after typing your password in, it reboots.

Sounds like it needs to b e wiped.
Old 05 May 2004, 03:37 PM
  #7  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

y doesnt bootin from floppy or CD work?

Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right?
Old 05 May 2004, 04:05 PM
  #8  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

I thought the Sasser worm only executed on starting windows?
Old 05 May 2004, 04:50 PM
  #9  
Jerome
Scooby Regular
Thread Starter
 
Jerome's Avatar
 
Join Date: Sep 2000
Posts: 4,460
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by bioforger
y doesnt bootin from floppy or CD work?

Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right?
No backup of any sort. Glad it's not my PC.
Old 05 May 2004, 04:59 PM
  #10  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

You are SOL then. Reinstall required.
Old 05 May 2004, 05:18 PM
  #11  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Hang on, you don't need to log onto the machine to remotely edit the registry.

Get the PC to the CTRL-ALT-DELT screen and leave.

Fire up RegEdit on another PC on the LAN.

On the Registry menu, choose "Connect Network Registry"

Find the infected PC or type in it's name.

Navigate to the key suba posted and delete it.

That should do the trick.
Old 05 May 2004, 06:41 PM
  #12  
greasemonkey
Scooby Regular
 
greasemonkey's Avatar
 
Join Date: Nov 2003
Location: where the wild roses grow
Posts: 5,122
Likes: 0
Received 0 Likes on 0 Posts
Default

Assuming of course the PC is networked.

If it's not, have you tried starting the PC in Safe Mode Jerome? (repeatedly hit F8 as the POST sequence ends, when the startup menu shows select Safe Mode).
Old 05 May 2004, 08:38 PM
  #13  
Jerome
Scooby Regular
Thread Starter
 
Jerome's Avatar
 
Join Date: Sep 2000
Posts: 4,460
Likes: 0
Received 0 Likes on 0 Posts
Default

I should have mentioned the PC isn't networked.

In safe mode it still reboots.

I think it's fecked.
Old 05 May 2004, 08:42 PM
  #14  
greasemonkey
Scooby Regular
 
greasemonkey's Avatar
 
Join Date: Nov 2003
Location: where the wild roses grow
Posts: 5,122
Likes: 0
Received 0 Likes on 0 Posts
Default

Yep, you're in trouble there. Have a look at Microsoft.com and the antivirus provider sites to see if there's a patch you can apply via a command prompt.

If not you're probably going to have to run a reinstall/repair.
Old 05 May 2004, 08:58 PM
  #15  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

No network. ERD Commander will let you boot from a CD and access the registry to edit out the keys.

If the machine config isn't that valuable, slave the HD up to another PC or do a parallel install of Windows to copy the data off. Then blow it away and rebuild.
Old 05 May 2004, 11:21 PM
  #16  
ajm
Scooby Regular
 
ajm's Avatar
 
Join Date: Sep 2002
Location: The biosphere
Posts: 7,824
Likes: 0
Received 0 Likes on 0 Posts
Default

In safe mode it still reboots.
Is it definately the virus causing this then? Because the reg key HKLM\software\microsoft\windows\currentversion\run should not run in safe mode!
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Abx
Subaru
22
09 January 2016 05:42 PM
PetrolHeadKid
Driving Dynamics
10
05 October 2015 05:19 PM
T.K
General Technical
10
02 October 2015 11:35 AM
the shreksta
Other Marques
26
01 October 2015 02:30 PM
minguela
Wheels And Tyres For Sale
0
29 September 2015 11:28 AM



Quick Reply: Sasser problem - a countdown of zero seconds...



All times are GMT +1. The time now is 12:56 PM.