Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Windows XP Embedded infected with Sasser Virus

73 views
Skip to first unread message

David Porter

unread,
May 5, 2004, 10:19:32 AM5/5/04
to
Does anyone have any advice on how to remove this virus
from my Windows XP Embedded systems.

Hurdles run into so far:
- My OS is in need of many critical updates.
- My system is rebooting about every 2 minutes leaving
me little opporunity to update the system.
- I have not found a cumulative update (Service Pack) on
the Microsoft Windows XP Embedded website.
- There is no Safe Mode functionality (F8) to use to
prevent the reboot. This method was very successful with
my Windows XP Profressional systesm
- Downloaded the Windows XP Embedded version of the
Sasser patch (KB835732) but it will not install, I keep
getting a QFE install error.

Doug Hoeffel

unread,
May 5, 2004, 11:53:53 AM5/5/04
to
David:

Try to stop the rebooting by using "shutdown -a".

Also, google for MS04-011 and avserv for help in trying to remove the virus
once you stop the rebooting.

HTH... Doug
"David Porter" <dp20...@ncr.com> wrote in message
news:8c0801c432ab$fc528780$a301...@phx.gbl...

David Porter

unread,
May 5, 2004, 1:47:28 PM5/5/04
to
Doug,

Thanks. I downloaded the Win XPE version of the patch
but it will not install. I receive the following error.

"QFE Installer Error. WEUpdate cannot retriece
information need for setup[ from databse. Setup cannot
continue."

I noticed on the update pages a notice stating "THESE
PATCHES ARE FOR THE DEVELOPMENT DATABASE, NOT THE
INSTALLED IMAGE" which is probably why I can't update the
system. How the hell, do you update a deployed system?

However, to allay the problem temporarily I used the
information found on Microsoft's Security page
(http://www.microsoft.com/security/incident/sasser_printxp
.asp)

The systems are running with no incident so far but I
still can't run any of the security or critical patchs on
the systems as I get the same error for each of update.
If you can't tell I'm not an Win XP Embedded pro. I'm an
end user using the software for kiosks.

>.
>

KM

unread,
May 5, 2004, 1:55:57 PM5/5/04
to
David,

> Does anyone have any advice on how to remove this virus
> from my Windows XP Embedded systems.
>
> Hurdles run into so far:
> - My OS is in need of many critical updates.

http://msdn.microsoft.com/embedded/downloads/xp/critQFE/default.aspx

> - My system is rebooting about every 2 minutes leaving
> me little opporunity to update the system.
> - I have not found a cumulative update (Service Pack) on
> the Microsoft Windows XP Embedded website.

http://msdn.microsoft.com/embedded/downloads/xp/critQFE/default.aspx

> - There is no Safe Mode functionality (F8) to use to
> prevent the reboot. This method was very successful with
> my Windows XP Profressional systesm

Safe Mode is not supported on XPe.

> - Downloaded the Windows XP Embedded version of the
> Sasser patch (KB835732) but it will not install, I keep
> getting a QFE install error.

Check out Additional_Info_Q835732.RTF document at the bottom of this page:
http://www.microsoft.com/downloads/details.aspx?familyid=ab3c1dd3-3382-4f84-a486-f0d7dffcf01f&displaylang=en

--
KM,
BSquare Corporation


Doug Hoeffel

unread,
May 5, 2004, 3:27:37 PM5/5/04
to
David:

The patch you are trying to run is the one for updating Target Designer at
development time. Also, you can't load a Win XP Pro patch on XPe.

You need to run the DUA patch on your deployed images. Since you are a end
user, it seems that this patch should be given to you by whoever built the
image. Hopefully DUA was built into this deployed image.

HTH... Doug
"David Porter" <dp20...@ncr.com> wrote in message

news:8b0601c432c9$0877a2d0$a401...@phx.gbl...

anon...@discussions.microsoft.com

unread,
May 5, 2004, 5:23:16 PM5/5/04
to
Doug,

Thanks so much. I've just been given the DUA patch by
the internal staff who developed the imagel. Thanks for
your help!

>.
>

Russell

unread,
Jul 28, 2004, 12:11:01 PM7/28/04
to
Try MSCONFIG to boot into diagnostic mode. This will prevent startup programs from running, and you have a better chance to manually remove the virus.
-Russell
0 new messages