ScoobyNet.com - Subaru Enthusiast Forum

ScoobyNet.com - Subaru Enthusiast Forum (https://www.scoobynet.com/)
-   Computer & Technology Related (https://www.scoobynet.com/computer-and-technology-related-34/)
-   -   Sasser problem - a countdown of zero seconds... (https://www.scoobynet.com/computer-and-technology-related-34/324901-sasser-problem-a-countdown-of-zero-seconds.html)

Jerome 04 May 2004 10:13 PM

Sasser problem - a countdown of zero seconds...
 
How do you get into a laptop that has been hit by the Sasser virus which, upon logging on, immediately reboots?

When it first got hit the countdown was 5 minutes. The user (the sister of my boss) ignored each countdown and reboot until the up time was less than 30 seconds(!). By the time my boss got to look at it, it was too late - he didn't have enough time to fix it. Now the countdown time is zero seconds.

One of the support guys at work has looked at the machine and can't even get in via safe mode and/or via the admin account. Booting via a floppy or CD doesn't work either.

Other than wiping the hard drive, is there a way of fixing this machine?

The machine is running XP.

ChrisB 04 May 2004 10:17 PM

Remotely edit the registry to remove the keys from \Run?

suba 04 May 2004 10:33 PM

and the reg key to delete is...

HKLM\software\microsoft\windows\currentversion\run

on the right pane, there should be something "uncheck.... %..." sorry i cant remember the exact line but it's something like in the quote.

Jerome 05 May 2004 03:27 PM

How do you edit the registry if you can't get into the system?

Can you edit the registry from BIOS?

ChrisB 05 May 2004 03:30 PM

From another PC over the network (assuming you have a network and a second PC!)

That's presuming the shut down countdown starts when you log on, not as the system boots.

Jerome 05 May 2004 03:35 PM

The shutdown is immediate - the moment you hit return after typing your password in, it reboots.

Sounds like it needs to b e wiped.

bioforger 05 May 2004 03:37 PM

y doesnt bootin from floppy or CD work? :confused:

Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right? ;)

Boro 05 May 2004 04:05 PM

I thought the Sasser worm only executed on starting windows?

Jerome 05 May 2004 04:50 PM


Originally Posted by bioforger
y doesnt bootin from floppy or CD work? :confused:

Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right? ;)

No backup of any sort. Glad it's not my PC. ;)

bioforger 05 May 2004 04:59 PM

You are SOL then. Reinstall required.

ChrisB 05 May 2004 05:18 PM

Hang on, you don't need to log onto the machine to remotely edit the registry.

Get the PC to the CTRL-ALT-DELT screen and leave.

Fire up RegEdit on another PC on the LAN.

On the Registry menu, choose "Connect Network Registry"

Find the infected PC or type in it's name.

Navigate to the key suba posted and delete it.

That should do the trick.

greasemonkey 05 May 2004 06:41 PM

Assuming of course the PC is networked.

If it's not, have you tried starting the PC in Safe Mode Jerome? (repeatedly hit F8 as the POST sequence ends, when the startup menu shows select Safe Mode).

Jerome 05 May 2004 08:38 PM

I should have mentioned the PC isn't networked.

In safe mode it still reboots.

I think it's fecked.

greasemonkey 05 May 2004 08:42 PM

Yep, you're in trouble there. Have a look at Microsoft.com and the antivirus provider sites to see if there's a patch you can apply via a command prompt.

If not you're probably going to have to run a reinstall/repair.

ChrisB 05 May 2004 08:58 PM

No network. ERD Commander will let you boot from a CD and access the registry to edit out the keys.

If the machine config isn't that valuable, slave the HD up to another PC or do a parallel install of Windows to copy the data off. Then blow it away and rebuild.

ajm 05 May 2004 11:21 PM


In safe mode it still reboots.
Is it definately the virus causing this then? Because the reg key HKLM\software\microsoft\windows\currentversion\run should not run in safe mode!


All times are GMT +1. The time now is 12:25 PM.


© 2024 MH Sub I, LLC dba Internet Brands