Unoffical empeg BBS

Quick Links: Empeg FAQ | RioCar.Org | Hijack | BigDisk Builder | jEmplode | emphatic
Repairs: Repairs

Topic Options
#219417 - 23/06/2004 07:24 Korgo virus
Phoenix42
veteran

Registered: 21/03/2002
Posts: 1424
Loc: MA but Irish born
Anyone know if Service Pack 2 and MS04-011 is sufficent to protect against this virus, I'm getting alot of conflicting info and would like the BBS opinion.

Thanks

Top
#219418 - 23/06/2004 07:41 Re: Korgo virus [Re: Phoenix42]
Roger
carpal tunnel

Registered: 18/01/2000
Posts: 5682
Loc: London, UK
All the blurb that I can find says that it spreads by using the LSASS vulnerability, which is the one that MS04-011 fixes.

What conflicting information have you had?
_________________________
-- roger

Top
#219419 - 23/06/2004 07:52 Re: Korgo virus [Re: Roger]
Phoenix42
veteran

Registered: 21/03/2002
Posts: 1424
Loc: MA but Irish born
With regards to the need for SP4 for full protection.
But the latest I hearing from the beast is the SP4 is not required.

There is a file that can be created that if it exists that will render the virus useless, like how the presents of .....

here is the MS page
http://www.microsoft.com/cze/security/incident/sasser_script_dcpromo.asp

essentially create c:\winnt\debug\dcpromo.log and make it read only will prevernt LSASS.EXE from rebooting PCs will attempting to clean them

Top