Tech ARP Forums

Go Back   Tech ARP Forums > Software Discussion > General Software
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Software This is the forum for general discussions about software.

Reply
 
LinkBack Thread Tools
Old 3rd Jan 2006, 06:39 AM   #11 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Exclamation

Quote:
On December 31st, a new and improved version of the WMF exploit had been published. The new exploit generated WMF files that were different enough to bypass nearly all Anti-Virus and IDS signatures. Different methods of distributing the virus, such as e-mails and instant messenger chats have already been seen in the wild, as more and more worms and trojans have been utilising the exploit to gain access to computers running the Windows operating system.

SANS and many other security sites recommend un-registering Shimgvw.dll (Microsoft picture and fax viewer) and using the unofficial patch to protect aginst the virus, until Microsoft can release an official patch. A virus scanner isn't enough to protect against some of the more advanced variants of the exploit.
SANS Internet Storm Center article
F-Secure Weblog
Unofficial patch site
__________________
acedriver is offline   Reply With Quote
SPONSOR

Old 6th Jan 2006, 01:47 AM   #12 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 30,382
Reputation: 3147
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 68
Default

Quote:
Originally Posted by acedriver
until Microsoft release a patch, you should unregister the dll..
Unregistering it right away!!
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 6th Jan 2006, 05:39 AM   #13 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Exclamation

WMF patch released early.

Security Update for Windows XP (KB912919)

Here's the other platforms also:
Security Update for Windows Server 2003 (KB912919)

Security Update for Windows 2000 (KB912919)

Security Update for Windows XP x64 Edition (KB912919)

Security Update for Windows Server 2003 64-bit Itanium Edition (KB912919)

The Security bulletin ( MS06-001 ) is now available and confirms this covers the WMF vulnerability.

Graphics Rendering Engine Vulnerability - CVE-2005-4560:
Quote:
A remote code execution vulnerability exists in the Graphics Rendering Engine because of the way that it handles Windows Metafile (WMF) images. An attacker could exploit the vulnerability by constructing a specially crafted WMF image that could potentially allow remote code execution if a user visited a malicious Web site or opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Recommendation for updating:

1. Reboot your system to clear any vulnerable files from memory
2. Download and apply the new patch
3. Reboot
4. Uninstall the unofficial patch, by using Add/Remove Programs on single systems. If you used msi to install the patch on multiple machines you can uninstall it with this:
msiexec.exe /X{E1CDC5B0-7AFB-11DA-8CD6-0800200C9A66} /qn
5. Re-register the .dll if you previously unregistered it (use the same command but without the "-u"):
regsvr32 %windir%\system32\shimgvw.dll
6. Reboot one more time just for good measure

http://isc.sans.org/
__________________

Last edited by acedriver : 6th Jan 2006 at 05:45 AM.
acedriver is offline   Reply With Quote
Old 6th Jan 2006, 05:45 AM   #14 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 30,382
Reputation: 3147
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 68
Default

Argghhh!!! I JUST installed the temporary patch!!!

Thanks for the update!
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 6th Jan 2006, 08:05 AM   #15 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 26,975
Reputation: 4108
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 74
Default

Cool thanks for the update!
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 4th Feb 2006, 02:09 PM   #16 (permalink)
Newbie
 
Join Date: 31 Jan 2006
Location: Florida
Posts: 12
Reputation: 10
buildcustompc is on a distinguished road
Rep Power: 0
Default

I got this infection on my computer a couple times and it wasn't pretty. It contiually pops up that infested box in the bottom right and doesn't let you change you backround. Ad-aware detects some of it and removes it but it reinstalls itself. I have to do a complete reformat/reinstall to get rid of it. Thanks for the info about what this was!

Will
buildcustompc is offline   Reply With Quote
Old 4th Feb 2006, 05:49 PM   #17 (permalink)
Super Active
 
1031982's Avatar
 
Join Date: 25 Feb 2003
Location: USA
Posts: 1,585
Reputation: 285
1031982 is a jewel in the rough1031982 is a jewel in the rough1031982 is a jewel in the rough
Rep Power: 9
Default

I use ACDsee, because it's not made fomr MS.
__________________
Running : Gigabyte EP45-DS3R, Intel E7200 C2D, 2GB DDR2 Dual Channel, WD Raptor 74GB, WD 500 GB HDD, ASUS 16X DVD-ROM, LiteOn 16X DVD+/-RW, 1.44 MB Floppy, ATI Radeon HD 3450, Dell 2005FPW, and a SB Audigy2 ZS PRO with Logitech Z5300e speakers.
1031982 is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft's nightmare inches closer to reality! Dashken News 0 26th Sep 2005 11:17 AM
Windows Services Exposed adn Expunge kayFX General Software 9 10th Jun 2005 09:32 PM


All times are GMT +8. The time now is 01:20 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2007 Tech ARP. All rights reserved.