Re: Gaobot worm

From: TJ Campana [MSFT] (tcampana_at_online.microsoft.com)
Date: 05/03/04


Date: Mon, 03 May 2004 20:41:17 GMT


>Hi Gloria,
>
>First of all, I highly recommend against posting with a real email address
>as it causes one to get spammed with a worm known as W32/Swen.
>
>It's nice to see someone taking a proactive stance on security and trying to
>insure their system is secure. There are a number of things one can do to
>prevent against infection with this, and also W32/Sasser.worm, which is
>similar but more common.
>
>1. Download the latest patches from Windows Update at
>http://windowsupdate.microsoft.com/.
>2. If you have Windows XP, turn on the firewall that comes with it.
>3. If you do not have Windows XP and do not have your own firewall, download
>one free from http://www.zonealarm.com/.
>4. Keep an updated antivirus program. If you do not have one, you can
>download one free from http://www.grisoft.com/.
>
>Hope this helps!
>
>Sincerely,
>Benjamin "Trafton" Johnstone-Anderson
>Microsoft MVP - Windows Security
>Remove "SPAM" from email address to reply!
>Security Manifest: www.msmvps.com/trafton/
>
>"gloriafgrady@sbcglobal,net" <anonymous@discussions.microsoft.com> wrote in
>message news:8DB7853E-C540-4E8D-96AE-A92AFF762661@microsoft.com...
>>I was informed by sbcglobal.net of a Gaobot Worm. How can I tell if my
>>computer has been infected and how can I get rid of it
>
>
>
Gloria,

Benjamin is absolutely correct. The best offense that we have at this time is a good defense. I would like to elaborate on the "Download the latest
patches" theme than Benjamin alluded to in the previous post. If you are running XP or 2000 then you can set the system up to download the patches
automatically. I have included an article below to help you set this up:

http://support.microsoft.com/default.aspx?scid=KB;EN-US;327838

Set this up and if you have a Broadband connection with a firewall this is a great way to make sure that you are up to date with critical patches. You
should also visit http://windowsupdate.microsoft.com regularly (weekly).

Virus scanners are also a must in today's world! If you do not have one you can even download them for free off the internet at this time. Do a GOOGLE
search for free "virus scan software" and you will see several options from free versions to free online scans. All are great tools to check to see if you are
infected. Again the AV software is only as good as the virus definitions present on the system, so you will have to schedule this to update frequently as
well.

In short, it is a jungle out there and it is important to keep your systems up to date with AV software, OS Patches and a good firewall.

T.J. Campana [MSFT]
Microsoft EPS Security

-- 
This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at 
http://www.microsoft.com/info/cpyright.htm 
Note:  For the benefit of the community-at-large, all responses to this message are best directed to the newsgroup/thread from which they originated.  


Relevant Pages

  • Re: Windows xp (Home Edition) updates. Yes or no???
    ... >> downloading rhese updates. ... >And then going another level and explain the specific "additions" to Windows ... > Why you should use a computer firewall.. ... >and some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: WindowsXP slower after reinstall.
    ... > Did you get on the Internet unprotected by a firewall or antivirus? ... > Also - did you test your hardware before reinstalling - it could be a bad ... > will have to do whatever you did before to get them installed or download ... > You can see the critical patches released for a given ...
    (microsoft.public.windowsxp.basics)
  • Re: Windows xp (Home Edition) updates. Yes or no???
    ... > downloading rhese updates. ... And then going another level and explain the specific "additions" to Windows ... Why you should use a computer firewall.. ... and some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: WindowsXP slower after reinstall.
    ... > Did you get on the Internet unprotected by a firewall or antivirus? ... > Also - did you test your hardware before reinstalling - it could be a bad ... > will have to do whatever you did before to get them installed or download ... > You can see the critical patches released for a given ...
    (microsoft.public.windowsxp.basics)
  • Re: Bridge.dll file
    ... I have Windows ... > How do I download a new bridge dll file or do I even need to do that? ... by the normal home user and in cooperation with a good firewall, ... I see that AntiVirus software is an absolute necessity given ...
    (microsoft.public.windowsupdate)