The F-Sasser utility disinfects computers infected with the
following Sasser worm variants:
W32/Sasser.A
W32/Sasser.B
W32/Sasser.C
Disinfection procedure should be as follows:
1, Download and install the security fix for the MS04-011 (LSASS)
vulnerability from Microsoft:
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
2. Unpack the F-Sasser utility from the provided ZIP archive
either with WinZip or PkUnzip utilities. A trial version of
WinZip archiver can be downloaded from the following website:
http://www.winzip.com/ddchomea.htm
3. Run the unpacked F-Sasser.exe file from a hard disk to
eliminate the infection. You can run the utility by either
doubleclicking on it from Windows Explorer or you can start it
from a command interpreter (COMMAND.COM or CMD.EXE) by typing its
name at command prompt and pressing 'Enter' (for advanced users).
First the F-Sasser utility will kill Sasser worm's processes in
memory. Then the utility will remove Registry entries created by
the worm. Finally the utility will scan all the Windows Directory
for infected files and delete them. The log files 'c:\win.log' and
'c:\win2.log' are deleted also.
4. Restart a computer. After restart your system should be clean.