Welcome Guest ( Log In | Register)



2 Pages V   1 2 >  
Reply to this topicStart new topic
> Serious Wmf Windows Exploit, No-one is safe right now
Tyssen
post Jan 1 2006, 08:23 AM
Post #1



***********

Group: Members
Posts: 1,161
Joined: 9-May 05
From: Brisbane, QLD
Member No.: 6,818



This has blown up big time in the last 3 days: http://www.f-secure.com/weblog/
Go to the top of the page
 
+Quote Post
Inspiron
post Jan 1 2006, 09:06 AM
Post #2


Trap Grand Marshal Member
***********

Group: Members
Posts: 1,205
Joined: 25-March 05
Member No.: 4,883



Yeap.. This Wmf so far is not patched, and probably impossible to patch. I've read somewhere detailed before..

Here's the link
http://www.updatexp.com/wmf-exploit.html
Go to the top of the page
 
+Quote Post
zaqy
post Jan 2 2006, 12:36 PM
Post #3


Member [Level 1]
****

Group: Members
Posts: 55
Joined: 20-December 05
From: Jakarta - Indonesia
Member No.: 15,976



hmm .. i think i ever find it 1 weeks ago. i think this is normal virus or trojan. but it hard to be cleaned.


from this information i know it is wmf exploit.

i will to give you solution i ever do if your computer is infected

1.update all of your antivirus definitions
2.try to find ad-aware personal ( www.lavasoft.com ) and update definitions too
1 recomended personal because this is free for private use
3.after you download the definition and the software in your pc ,reboot your pc and start ing it in SAFE MODE

4. run all scan using your anti virus and ad-aware personal ( you can try other spyware remover) after virus found you can remove it.

5. restart your pc after you scan it

6. just waiting for 5 minutes for make your pc clean


this is for XP user.

you can me other suggestion if you have other best solution ...

thank you
Go to the top of the page
 
+Quote Post
Tyssen
post Jan 2 2006, 10:27 PM
Post #4



***********

Group: Members
Posts: 1,161
Joined: 9-May 05
From: Brisbane, QLD
Member No.: 6,818



QUOTE(zaqy @ Jan 2 2006, 10:36 PM)
i think this is normal virus or trojan. but it hard to be cleaned.

No it's not. Did you even read the link? rolleyes.gif
Go to the top of the page
 
+Quote Post
rejected
post Jan 3 2006, 05:01 AM
Post #5


{([Mod])}
*********

Group: Members
Posts: 710
Joined: 30-October 04
From: Texas
Member No.: 2,058



I've already had an encounter with the .wmf file, it downloaded and installed several spywares and fake anti-virus programs onto my computer. A little pop-up that looked like a windows update button appeared on my task bar, and it said something about my computer being infected, and that it needs to install the newest up-to-date anti malware program. I tried to X it out, but missed, and it installed "SpyAxe 3.0" on my computer.. and I had great difficulty removing it.

If you get exploited by the WMF file, I suggest looking at the processes running, and looking for abnormal ones and researching them. If you find them to be spyware, etc, then search google.com for ways to remove them.

The process running on my computer was mssearchnet.exe, and I searched and found a way to do it. If you need any help removing your spyware, PM me, or post in this topic for more help smile.gif.
Go to the top of the page
 
+Quote Post
_TyIzaeL_
post Jan 5 2006, 02:57 AM
Post #6


Newbie [Level 1]
*

Group: Members
Posts: 20
Joined: 16-November 05
Member No.: 14,379



I've encountered the .wmf file also. It was downloaded into my temp directory, it managed to open a windows fax viewer window but was blocked at that point by my anti-virus.
Go to the top of the page
 
+Quote Post
Inspiron
post Jan 5 2006, 05:10 AM
Post #7


Trap Grand Marshal Member
***********

Group: Members
Posts: 1,205
Joined: 25-March 05
Member No.: 4,883



Some .wmf files indeed contain virus inside their bytecodes. But the exploit in .wmf format is more than just capable of storing viruses inside them. It's an exploit that cannot be fixed. So virus writers now know of this exploit, and certainly uses them to intrude your data. If that's the case, and since this exploit cannot be solved, it will be undetectable by firewalls and antivirus softwares. Probably that ones that you had encountered were indeed natural virus files that were not based on that exploit. It will be even more damaging with its based on the exploit.
Go to the top of the page
 
+Quote Post
Tyssen
post Jan 5 2006, 08:19 AM
Post #8



***********

Group: Members
Posts: 1,161
Joined: 9-May 05
From: Brisbane, QLD
Member No.: 6,818



The guy who posted his own patch in the first link I gave has had so much traffic to his site that his ISP shut his site down. blink.gif
Go to the top of the page
 
+Quote Post
zaqy
post Jan 5 2006, 01:55 PM
Post #9


Member [Level 1]
****

Group: Members
Posts: 55
Joined: 20-December 05
From: Jakarta - Indonesia
Member No.: 15,976



QUOTE(Tyssen @ Jan 3 2006, 05:27 AM)
No it's not. Did you even read the link?  rolleyes.gif
*



sorry friend i mean at the first sight i think this is only normal spyware.but after 3 days i can't clean that pc .. so i think this is serious .. smile.gif