Become a supporter to remove this ad

User Tag List

+ Reply to Thread
Results 1 to 6 of 6

Thread: New Virus

  1. #1
    Member snowman95's Avatar
    Join Date
    May 2005
    Liked
    0 times
    Posts
    2,752
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Grabbed this info and thought it would be of use to everyone: pay attention kids



    Originally posted by MonkeyPirate

    WHAT IS IT?
    There is a new exploit out that uses WMF (windows metafile format) files to infect a computer. All you have to do to get infected is view a webpage that has the image on it. That means the forums can be a vector for infection too. (In fact, user Blue Reptile has embedded a virus in his signature today and was already permabanned for it.)


    WHAT DOES IT AFFECT?
    The exploit affects Firefox, Internet Explorer, and any other browser that downloads the file into the cache on the local machine. The file could also be a WMF renamed to any other image, or even a text filetype. Anything that puts the image exploit onto your computer or opens it up in windows fax viewer or the part of windows that generates thumbnails of WMF files is a vulnerability. This means any vector that puts the image onto your computer (wget, browser, email, IM, etc) can potentially cause the problem.

    This affects anyone on Windows (98, 98SE, ME, 2000, XP, 2003). USING FIREFOX DOES NOT ELIMINATE THE RISK as the file is still downloaded to your cache in most cases, but it does reduce your chances somewhat since the image is often not displayed in the browser. But if you then interact with the file in any way (thumbnail it, Google Desktop) that causes it to be handled by the windows GDI responsible for WMF then you will have problems. Once again, YOU CAN BE CAUGHT BY THIS EXPLOIT EVEN IF THE IMAGE DOES NOT SHOW IN THE BROWSER. If you use Windows, your system is vulnerable.




    WHAT DOES IT DO?
    The exploit can be used to drop viruses, trojans, installers etc onto your computer when the exploit is activated (when the file is parsed by the part of windows with the problem). There have been several reports of trojans being downloaded, which then download other things, other spyware, etc. Some of these are "SpyAxe", "AYL" trojan downloader, "ASC" trojan, and other stuff.


    For further technical information please see the SH/SC thread - http://forums.somethingawful.com/showthrea...hreadid=1759573




    WHAT YOU CAN DO TO HELP PROTECT YOURSELF
    1. SCAN YOUR COMPUTER - NOD32 TRIAL VERSION (update definitions right away after installing - they auto-update but you want to be sure you have the latest)
    Even if you think you are safe, scan your Windows computer anyway. ClamWin appears to catch this, but it doesn't have a realtime scanner. SAV Corporate 10.2 does not catch it (yet) and Symantec's own site says that it never may due to something about how the virus works. AVG, McAfee, Trend are unknowns at this point. I have personally tested NOD32 and found that it's AMON on-access scanner stopped the image as soon as it was saved to the cache. NOTE: SCAN ALL FILES. Some AV solutions only scan "infectable" files and do not scan image files because the program thinks they are safe. Check for an option to scan all file types and make sure that is enabled.

    2. USE AN ALTERNATIVE BROWSER - Using Firefox or an alternative browser will reduce your risk because it does not display the image. However the image is still downloaded to your cache, and some browsers prompt you to open the file - which you should not do!

    3. TURN OFF SALR's feature that makes text links into images. If you have that feature turned on, someone could make just a text link that displays the infected image in your browser.

    4. TURN OFF GOOGLE DESKTOP or anything else that does indexing of files on your computer.

    5. THE GENERAL STUFF - Don't go to links you don't trust, don't open files you aren't expecting, including suspicious email or IM's, etc.

    6. KEEP ON TOP OF WINDOWS UPDATES - Hopefully they can fix this one quickly, but you really should be up-to-date on everything else anyway.

    7. You can try unhooking the part of Windows that views those image files. To do this, click Start -> Run and type regsvr32 /u shimgvw.dll then press OK. You will get a confirmation message. To undo this, repeat but type regsvr32 shimgvw.dll instead. Note: This only has a minimal benefit - it only disables the image viewer itself. It doesn't prevent against viewing the exploit image in Internet Explorer, for example.




    BOTTOM LINE: If you use Windows, you will not be 100% safe from this exploit until the problem in windows is patched - there is no patch yet.

  2. #2
    Member PHOBiA's Avatar
    Join Date
    Dec 2004
    Location
    Joondalup
    Liked
    0 times
    Posts
    821
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    cheers for info!
    bikeless

  3. #3
    Member Phildo's Avatar
    Join Date
    Apr 2005
    Location
    South Perth
    Motorbike
    Aprilia SXV550, GasGas FSE450 & Kawasaki Balius
    Liked
    77 times
    Posts
    2,708

    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Why I love my Macs: Macs don't get viruses



    Power Mac G5/2.5GHz Dual Processor
    PowerBook G4/1.67 17"
    One owner. Only driven gently on Sundays. Sold to best offer. First to see will buy. Reward offered for safe return. Coming soon to a cinema near you. Available for a limited time only.

    My waterbed broke this morning. Oh, I don't have a waterbed. Bugger.

  4. #4
    Member Ferris's Avatar
    Join Date
    May 2004
    Location
    BNE
    Motorbike
    09 Busa
    Liked
    3 times
    Posts
    5,111
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yeah, coz no one can be fucked writing a virus for them, as not enough people use them. Every time a mac person ever pipes up, this is the only reason why they do:"I don't get viruses" they stammer weakly. Big fucking deal. What else doesn't your mac get? Decent software, games or support.

    Work Buy Consume Die

  5. #5
    Inactive Member Foofie Foofie's Avatar
    Join Date
    Mar 2005
    Location
    Shar'n a room with Snoop Dogg in m'fukin Compton.
    Liked
    0 times
    Posts
    5,835
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hahahahahhahaha Ferris .

    My mate owns Mactherapy , one of the leading Mac people in perth , and even he will say "Get a pc ..... " hahaha , or better yet "Use Linux" .

  6. #6
    lee
    lee is offline
    Member lee's Avatar
    Join Date
    May 2006
    Motorbike
    pink r1200gs
    Liked
    9 times
    Posts
    14,654
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally posted by Ferris@Dec 29 2005, 04:03 PM
    What else doesn't your mac get?* Decent software, games, more than one mouse button or support.
    [snapback]207548[/snapback]
    microsoft werd.

+ Reply to Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.6.0