Tech ARP Forums

Go Back   Tech ARP Forums > Software Discussion > General Software
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Software This is the forum for general discussions about software.

Reply
 
LinkBack Thread Tools
Old 29th Dec 2005, 11:54 AM   #1 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Exclamation Windows zero day nightmare exploited

Since no news about it is posted here..

F-SECURE, Bugtraq and a number of other security aware outfits have warned of a zero day vulnerability that's being actively exploited as we write.

Fully patched Windows XP SP2 machines are vulnerable and there's no known fix as yet.
A number of trojans are being distributed using the vulnerability, related to Windows' image rendering.

F-Secure says you can get blatted if you visit a site with an image file containing the exploit. IE users may automatically be infected. Firefox users can get infected if the image file is downloaded. There's more solid advice at F-Secure. We await a patch from Microsoft.

Full article and source

More info from F-Secure

------
Microsoft has officially put out a statement, check it out at:

http://www.microsoft.com/technet/security/...ory/912840.mspx

It looks some folks are being able to mitigate or momentarily fix the vulnerability by typing the following command:

REGSVR32 /U SHIMGVW.DLL

-------
Complete step:

To un-register Shimgvw.dll, follow these steps:

1. Click Start, click Run, type regsvr32 /u shimgvw.dll, and then click OK.

2. A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.

Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with regsvr32 shimgvw.dll.
__________________
acedriver is offline   Reply With Quote
SPONSOR

Old 29th Dec 2005, 02:02 PM   #2 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 26,975
Reputation: 4108
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 74
Default

Crap. I use Windows Picture and Fax Viewer...
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 29th Dec 2005, 02:22 PM   #3 (permalink)
Jet
Hold me back! I can't stop posting!!!
 
Jet's Avatar
 
Join Date: 5 Sep 2004
Posts: 6,694
Reputation: 1274
Jet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud ofJet has much to be proud of
Rep Power: 23
Default

If not using Windows Picture and Fax Viewer, what should we use?
Jet is offline   Reply With Quote
Old 29th Dec 2005, 03:00 PM   #4 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Default

Quote:
Originally Posted by Jet
If not using Windows Picture and Fax Viewer, what should we use?
Irfanview, XnView, Picasa, Acdsee

-------
more info:
Quote:
If you are infected you'll immediately notice because your desktop background will turn either black or blue and it will have a huge warning saying that you are infected, there will also be a warning and icon on your system tray telling you the same and prompting you to click on it to resolve the problem, however both warnings are fake and part of the virus to trick people into clicking and installing the rest of the trojan. At that point without clicking you will already be infected with a system you cannot change the desktop background to, several changes made to your registry and several .exe files placed in different areas of your system, you will also see that your system enters in a loop where everytime you restart the computer the same program tries to make you click and install the program, if you do then your system will be even more compromised.

This virus also tricks people cause it sends you to a page where supposedly you are going to buy an anti-spyware or anti-virus program, you ll be sending your information to a bogus site which will not give you any software at all. So far this is what I know about the virus, but there's lots more it can do and it appears there's several dangerous variants of it on the wild.
from neowin



That's what you will see on your system tray too if you are infected.
__________________
acedriver is offline   Reply With Quote
Old 29th Dec 2005, 03:09 PM   #5 (permalink)
ARP Webmaster
 
peaz's Avatar
 
Join Date: 13 Oct 2002
Location: http://atpeaz.placidthoughts.com/
Posts: 8,515
Reputation: 1673
peaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant future
Rep Power: 31
Default

faststone viewer is also a pretty good viewer...
peaz is offline   Reply With Quote
Old 29th Dec 2005, 03:47 PM   #6 (permalink)
beat around the bush
 
aKho's Avatar
 
Join Date: 3 Jun 2005
Location: Kuching, Sarawak
Posts: 2,806
Reputation: 1169
aKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud of
Rep Power: 17
Default

lucky i using ACDSee..
windows picture viewer not enough functions..
__________________
aKho is offline   Reply With Quote
Old 29th Dec 2005, 04:21 PM   #7 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Default

I think it doesn't care what image viewer you use. As long it is executed, the worm start. If the file is saved locally DO NOT EVEN HOVER OVER IT!! Even if its on your desktop without a preview it will allow the exploit to run.

The only workaround right now is to unregister SHIMGVW.DLL.
__________________
acedriver is offline   Reply With Quote
Old 29th Dec 2005, 04:36 PM   #8 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 26,975
Reputation: 4108
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 74
Default

So serious???
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 30th Dec 2005, 03:58 AM   #9 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 30,382
Reputation: 3147
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 68
Default

Hmm... I use Firehand Ember. It takes over the previewing and viewing of pictures. So do I still need to unregister that DLL?
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 30th Dec 2005, 08:37 AM   #10 (permalink)
Active
 
acedriver's Avatar
 
Join Date: 17 Apr 2004
Posts: 519
Reputation: 501
acedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of lightacedriver is a glorious beacon of light
Rep Power: 10
Default

until Microsoft release a patch, you should unregister the dll..
__________________
acedriver is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft's nightmare inches closer to reality! Dashken News 0 26th Sep 2005 11:17 AM
Windows Services Exposed adn Expunge kayFX General Software 9 10th Jun 2005 09:32 PM


All times are GMT +8. The time now is 04:29 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2007 Tech ARP. All rights reserved.