Re: sobig worm

From: Chris Jackson (chrisj_at_mvps.org)
Date: 08/29/03


Date: Fri, 29 Aug 2003 11:59:58 -0400


In this case, you can prevent infection by not opening attachments, keeping
your computer up to date using Windows Update, and running a firewall.

-- 
Chris Jackson
Software Engineer
Microsoft MVP - Windows XP
Windows XP Associate Expert
-- 
"p dehazya" <drwho12@msn.com> wrote in message
news:0d1601c36e42$a6850c20$a401280a@phx.gbl...
> Is there a protective patch available for this worm and
> its variants? I know there are extraction tools available,
> and that certain attachments are known to carry the worm,
> but I wish to install a patch to prevent infection.
>
> Thanks


Relevant Pages

  • Re: removing w32/sdbot.worm.gen
    ... Time to blow it away and start a new install. ... boot the Windows 2000 install CD-Rom or setup disks. ... because of the worm or something I dont know. ... the infection I cannot go to that Windows update site. ...
    (microsoft.public.win2000.general)
  • Re: READ THIS if you have problems with your RPC service, svchost.exe or similar.
    ... > We are on Yellow Alert....MSBLASTER worm - aka DCOM worm ... > Windows DCOM RPC Vulnerability announced July 16, ... > Infection sequence: ... SOURCE sends packets to port 135 tcp with variation of dcom.c exploit ...
    (microsoft.public.security)
  • Re: READ THIS if you have problems with your RPC service, svchost.exe or similar.
    ... > We are on Yellow Alert....MSBLASTER worm - aka DCOM worm ... > Windows DCOM RPC Vulnerability announced July 16, ... > Infection sequence: ... SOURCE sends packets to port 135 tcp with variation of dcom.c exploit ...
    (microsoft.public.windowsxp.security_admin)
  • Re: READ THIS if you have problems with your RPC service, svchost.exe or similar.
    ... > We are on Yellow Alert....MSBLASTER worm - aka DCOM worm ... > Windows DCOM RPC Vulnerability announced July 16, ... > Infection sequence: ... SOURCE sends packets to port 135 tcp with variation of dcom.c exploit ...
    (microsoft.public.win2000.security)
  • RE: Remote Procedure Call
    ... It appears you have been infected by the blaster worm. ... plus the Value "windows auto update" under the ... connecting to the internet. ... original infection. ...
    (microsoft.public.windowsxp.security_admin)