Computernerd22, excellent post.
Just have a few more techincal details to add
The actual registry entry Sasser makes is:
"avserve2.exe"="%Windir%\avserve2.exe" (or)
"avserve.exe"="%Windir%\avserve.exe" (Depending on the version of Sasser) in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(this is for those bold enough to do registry editing themselves.)
Symantec also provides a removal tool known as FxSasser.exe which can be downloaded Here
For full instructions of what this tool does and how to use it, go Here
(it's about midway through the page).
btw Computernerd22, that Stinger is an awesome find. nice work.
note: Trojan.Adwaheck is apparently our newest pain in the ass. read more about it
Here




)
Reply With Quote