User Tip #185: Disable Windows Scripting Host ( WSH )

Hits: Failed to execute CGI : Win32 Error Code = 3


The majority of viruses recently have been email-based. They are often written in VBScript which is a scripting language used to automate tasks without user intervention (or perhaps, one even knowing the script is running). Microsoft built the Windows Scripting Host (WSH) as a application to run vbscript programs. It ships as an integral part of Windows 2000 and Windows XP. WSH is also included when one downloads Internet Explorer 5. WSH can be used to get access to the Windows commandshell, file system, and registry. Lots of people know vbscript. Its complexity is low, at least, the complexity to write virus code.

To find out if the Windows Scripting Host is enabled on your PC:

If its enabled, the Windows Script Host Settings dialog box will poppup.

You can protect yourself from these malicious programs if you have up-to-date antivirus code resident. This is becoming an absolute requirement in corporate environments. If you don't have that level of protection, you might want to block the vbscripting threat by disabling the Windows Scripting Host which is the agent that executes the .vbs files. There are several methods which are compatible for Windows NT / Windows 2000 and Windows XP:




details of how specific attacks work and how to protect against them



step-by-step guide to defending against hacker intrusions