![]() |
| Register | |||||||
| General Software This is the forum for general discussions about software. |
![]() |
| | LinkBack | Thread Tools |
| | #1 (permalink) |
| Active Join Date: 17 Apr 2004
Posts: 519
Reputation: 501 ![]() ![]() ![]() ![]() ![]() ![]() Rep Power: 10 | Since no news about it is posted here.. F-SECURE, Bugtraq and a number of other security aware outfits have warned of a zero day vulnerability that's being actively exploited as we write. Fully patched Windows XP SP2 machines are vulnerable and there's no known fix as yet. A number of trojans are being distributed using the vulnerability, related to Windows' image rendering. F-Secure says you can get blatted if you visit a site with an image file containing the exploit. IE users may automatically be infected. Firefox users can get infected if the image file is downloaded. There's more solid advice at F-Secure. We await a patch from Microsoft. Full article and source More info from F-Secure ------ Microsoft has officially put out a statement, check it out at: http://www.microsoft.com/technet/security/...ory/912840.mspx It looks some folks are being able to mitigate or momentarily fix the vulnerability by typing the following command: REGSVR32 /U SHIMGVW.DLL ------- Complete step: To un-register Shimgvw.dll, follow these steps: 1. Click Start, click Run, type regsvr32 /u shimgvw.dll, and then click OK. 2. A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box. Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer. To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with regsvr32 shimgvw.dll. |
| | |
| SPONSOR |
| |
| | #4 (permalink) | ||
| Active Join Date: 17 Apr 2004
Posts: 519
Reputation: 501 ![]() ![]() ![]() ![]() ![]() ![]() Rep Power: 10 | Quote:
------- more info: Quote:
![]() That's what you will see on your system tray too if you are infected. | ||
| | |
| | #7 (permalink) |
| Active Join Date: 17 Apr 2004
Posts: 519
Reputation: 501 ![]() ![]() ![]() ![]() ![]() ![]() Rep Power: 10 | I think it doesn't care what image viewer you use. As long it is executed, the worm start. If the file is saved locally DO NOT EVEN HOVER OVER IT!! Even if its on your desktop without a preview it will allow the exploit to run. The only workaround right now is to unregister SHIMGVW.DLL. |
| | |
| | #9 (permalink) |
| Da Boss Join Date: 10 Oct 2002 Location: In front of my ASUS F8V notebook!
Posts: 30,382
Reputation: 3147 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Rep Power: 68 | Hmm... I use Firehand Ember. It takes over the previewing and viewing of pictures. So do I still need to unregister that DLL? ![]()
__________________ Dr. Adrian Wong Tech ARP | Blog @ Tech ARP | The Free Trade Zone DYKT : The only offshore account I have is at the sand bank? We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer! My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs |
| | |
![]() |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Microsoft's nightmare inches closer to reality! | Dashken | News | 0 | 26th Sep 2005 11:17 AM |
| Windows Services Exposed adn Expunge | kayFX | General Software | 9 | 10th Jun 2005 09:32 PM |