w32.spybot.worm



I have detected a nasty worm on our server as w32.spybot.worm(symantec). It
changes a couple registry key configurations controlling DCOM. It also sets
itself to run on startup. However everytime I delete these keys they come
back. I have been adding service packs and patches today but still have
problems removing this bug. It says it is a file in Winnt\system32 however
I can not see it in safe mode, command prompt. I have all files to be shown
including system files. I have a SQL database on this system at SP2. I
have updated to SP4 for Windows 2000 and am applying patches. However it
keeps disabling the DCOM and users get access permission 70 denied when
trying to access database program. Currently when I scan it does not find a
virus but the registry changes continue to to change back to disable DCOM
and restrict anonymous access = 1 in LSA.


.



Relevant Pages

  • [Full-Disclosure] NTBUGTRAQ on DCOM
    ... So I have been running around recommending that everyone get DCOM disabled. ... Microsoft provides a wonderfully vague warning, ... Warning, if you disable DCOM, may you may lose operating system ... The local COM+ snap-in will not be able to connect to remote servers to ...
    (Full-Disclosure)
  • Re: DCOM Problems
    ... Windows Registry Editor Version 5.00 ... > It's a bug with Microsoft Word. ... > see if the error goes away, DCOM is a HUGE security risk anyway. ... > How to disable DCOM support in Windows ...
    (microsoft.public.win2000.general)
  • Re: DCOM Problems
    ... It's a bug with Microsoft Word. ... BUG: Word 2000 Version Key Doesn't Match Its Type Library Version ... see if the error goes away, DCOM is a HUGE security risk anyway. ... How to disable DCOM support in Windows ...
    (microsoft.public.win2000.general)
  • svchost.exe | exe.tsohcvs
    ... This has something to do with DCOM. ... To disable DCOM, change this value ... If EnableDCOM is not set to "Y," then all cross-computer ... I always go to windows updates and do ...
    (microsoft.public.windowsxp.security_admin)
  • Re: DCOM Error 10009
    ... How to disable DCOM support in Windows ... The W2K server has TCP set as ... > the primary default protocol and the only datagram protocol listed is IPX ...
    (microsoft.public.win2000.networking)