Microsoft leaves Window wide open

A security hole in a Microsoft Windows feature has not been removed since its first encounter with the virus 'Bubble Boy' in 1999.

"That kind of danger is still present today. The feature is not used by 99.9 percent of people, it should be the first thing removed from a computer when the machine is set up. Otherwise users are at risk of being attacked," Trend Micro spokesperson Andy Liou told ZDNet Australia.

Liou says script viruses written on programs such as VBScript and JavaScript make use of Microsoft's Windows Scripting Host - available on Windows 98 and 2000 - to activate themselves and infect other files.

Viruses which exploit scripts embedded in HTML automatically execute the moment the HTML page is viewed from a script-enabled browser. In other words, the user doesn't need to double click on the attachment for the virus to be run.

BubbleBoy was the first virus to take advantage of the Windows Scripting Host feature, which hit in 1999.

Liou says the virus was created to prove that a virus could be executed just by reading an email.

The treacherous Love Letter virus, which hit in May 2000, also took advantage of the Windows Scripting Host.

Liou says script viruses have been around for some time and are quite easy to protect.

"All the user has to do is remove the Windows Scripting Host from their machines, and the virus cannot be executed," Liou said.

A lot of users however, don't know about the vulnerabilities within the Windows feature, which is one of the reasons the spread of viruses is on the increase.

Liou believes the only users of the Windows feature these days are the virus writers themselves.

"I don't know anybody who uses the feature. By default, it comes installed. A lot of people don't know they have it. It should be completely removed," he said.

To remove the Windows Hosting Script feature, visit Trend Micro

Advertisement

Talkback 5 comments

    How about a link to a page tha ...Darrell Little -- 18/04/01

    How about a link to a page that helps people disable Windows Scripting Host?

    So how do you remove Windows S ...Anonymous -- 18/04/01

    So how do you remove Windows Scripting Host?

    To remove Windows Scripting Ho ...Anonymous -- 18/04/01

    To remove Windows Scripting Host from Win98
    click on control panel, Click on add/remove programs go to windows setup tab
    click on accessories then scroll down and untick
    windows scripting host...

    For Win 95 and Win NT: Open My ...Anonymous -- 18/04/01

    For Win 95 and Win NT:

    Open My Computer, click on View tab then select options, Click on file type tab, scroll down and remove VBSscript script file then ok.

    For Win2000:

    Open My Computer, click on tools tab then select Folder Options, click on file types tab then scroll down and delete VBSscript script file then ok.

    Home users may not use Windows ...Anonymous -- 20/04/01

    Home users may not use Windows Scripting Host but those of us managing networks can find it quite useful. I use it for software updates, information gathering, logon scripts etc on remote computers.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured