With regards to the need for SP4 for full protection.
But the latest I hearing from the beast is the SP4 is not required.

There is a file that can be created that if it exists that will render the virus useless, like how the presents of .....

here is the MS page
http://www.microsoft.com/cze/security/incident/sasser_script_dcpromo.asp

essentially create c:\winnt\debug\dcpromo.log and make it read only will prevernt LSASS.EXE from rebooting PCs will attempting to clean them