[thelist] failure notice (& CF TIP)

Richard H. Morris richard.morris at web-designers.co.uk
Wed Sep 19 05:54:10 CDT 2001


John Handelaar [genghis at members.evolt.org] wrote:

> -----Original Message-----
> Utterly unhelpful.  Way to go, Richard.
>
> The answer:
>
> 1	Look for all instances of README.EXE on your local
> 	disks and delete them
>
> 2	Search the registry for 'macrosoft' and remove the
> 	keys
>
> 3	Uninstall IIS and Windows Scripting Server on your
> 	desktop machine
>
> 4	Disable 'active scripting' in IE at all 4 security
> 	settings.  Better still, get Mozilla 0.9.4 instead
> 	'cos it's (believe it or not) more robust and doesn't
> 	suffer from the security bug which enables one
> 	of this worm's 6 or 7 methods of propagation.

Re: 4, just get a Mac and don't worry about Wintel executables? Just as
helpful advice...

You forgot to mention the hidden files load.exe and riched20.dll and the
changes made to system.ini if we're going to be pedantic.

There's still no excuse for web designers in particular who will be open to
attacks like this not running decent and up to date AV software and more
particularly having a policy in respect of executables and files sent to
them.

Good advice, I thought...

_/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
Richard. H. Morris, Web Designers Limited
~~ http://www.web-designers.co.uk ~~
"I'd rather have a full bottle in front of me
          than a full frontal lobotomy"
_/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/







More information about the thelist mailing list