New Windows exploit found - can infect your computer just by viewing an image

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Dubb

Platinum Member
Mar 25, 2003
2,495
0
0
I don't see how I could have gotten this, but I just tried to run windows update and got:

The site cannot continue because one or more of these Windows services is not running:

Automatic Updates (allows the site to find, download and install high-priority updates for your computer)
Background Intelligent Transfer Service (BITS) (helps updates download more quickly and without problems if the download process is interrupted)
Event Log (keeps a record of updating activities to help with troubleshooting, if needed)


I double checked and all those are on...hmmm. computer seems ok, norton automatically got the latest update ...but I'm starting to get suspicious.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: cbrsurfr
Heard about this at work. Tried it out on one of my builds and DEP stopped it everytime. That combined with SAV and Cisco security agent means I'm not worried.
The latest word is that software DEP doesn't work, but hardware DEP usually works. But not always. Your layered defense sounds great

I suspect this exploit will haunt the average home users for a long time to come... 3-year old Dell/eMachine/Compaq with no updates and a long-expired install of Norton Antivirus 2002, etc. ~ huh? I need to update it, why again...?

 

BriGy86

Diamond Member
Sep 10, 2004
4,538
1
91
Originally posted by: mechBgon
Originally posted by: cbrsurfr
Heard about this at work. Tried it out on one of my builds and DEP stopped it everytime. That combined with SAV and Cisco security agent means I'm not worried.
The latest word is that software DEP doesn't work, but hardware DEP usually works. But not always. Your layered defense sounds great

I suspect this exploit will haunt the average home users for a long time to come... 3-year old Dell/eMachine/Compaq with no updates and a long-expired install of Norton Antivirus 2002, etc. ~ huh? I need to update it, why again...?

son of a bitch!

(<- works in a tech shop) i supose i'll be seeing lots of new machines now
 

Rubycon

Madame President
Aug 10, 2005
17,768
485
126
What intel chips have hardware DEP?

I think of caulk when people talk about DEP probably because DAP makes it. :Q
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: BriGy86
trend micro FTW!
VirusScan Enterprise 8.0i generic buffer-overflow protections FTW*! (at work, anyway)






*when using Windows Explorer or Internet Explorer

 

aplefka

Lifer
Feb 29, 2004
12,016
2
0
Pretty sure it's been out for a while now, isn't this the one that's been going around on AIM where it looks like you're clicking on some image and then it's a virus? That's why I don't click any links when it comes out of nowhere and I wasn't talking to the person before.
 

BriGy86

Diamond Member
Sep 10, 2004
4,538
1
91
Originally posted by: mechBgon
Originally posted by: BriGy86
trend micro FTW!
VirusScan Enterprise 8.0i generic buffer-overflow protections FTW*! (at work, anyway)






*when using Windows Explorer or Internet Explorer

im guessing that its expensive and not found in retail stores
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: BriGy86
Originally posted by: mechBgon
Originally posted by: BriGy86
trend micro FTW!
VirusScan Enterprise 8.0i generic buffer-overflow protections FTW*! (at work, anyway)






*when using Windows Explorer or Internet Explorer

im guessing that its expensive and not found in retail stores
You got me there, it's a minimum 5-pack at their small-biz store They wouldn't dare sell it to consumers, the configuration is a bit overwhelming for home users :evil:

 

BriGy86

Diamond Member
Sep 10, 2004
4,538
1
91
by that config it seems as though it has the same effect as unpluging the cat 5 wire, lol

and as for that DEP option what does it exactly do?

*edit*

it also says that my CPU does not support DEP (AMD athlon XP 3000+)

is it worth having on anyway?
 

imported_goku

Diamond Member
Mar 28, 2004
7,613
3
0
Originally posted by: JJWalker
Originally posted by: amjohns5
Ugh, I just reformatted, and forgot my username/password for my 2 year subscription to Norton '06!!


I would look at that as a positive.
QFT
Get kaspersky, norton is garbage, absolute garbage that does sh!t for detecting viruses.
 

BriGy86

Diamond Member
Sep 10, 2004
4,538
1
91
Originally posted by: goku
Originally posted by: JJWalker
Originally posted by: amjohns5
Ugh, I just reformatted, and forgot my username/password for my 2 year subscription to Norton '06!!


I would look at that as a positive.
QFT
Get kaspersky, norton is garbage, absolute garbage that does sh!t for detecting viruses.

norton is better than mcafee , i suggest trend micro though, or even panda
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: BriGy86
by that config it seems as though it has the same effect as unpluging the cat 5 wire, lol
Hehe
and as for that DEP option what does it exactly do?

*edit*

it also says that my CPU does not support DEP (AMD athlon XP 3000+)

is it worth having on anyway?
AthlonXPs don't have hardware DEP, nopers. I'd turn it on for kicks if it were me, but I'd be counting on the antivirus software as the main line of defense, and my Limited user account as the next layer, plus common sense where possible.

I saw on F-Secure's blog that a very good programmer has made a temporary fix for WinXP systems: http://www.hexblog.com/2005/12/wmf_vuln.html

Anyway, what hardware DEP is supposed to do is to [ layman talking ] only allow code to execute from pages of memory that are specifically marked as executable [ / layman ], declawing some types of buffer-overflow attacks at the hardware level. Telling Windows to use that capability for all programs, not just core Windows components, is what apparently is needed in this case.

Here's a .WMV showing a security researcher deliberately walking into the exploit: http://www.sunbelt-software.com/ihs/alex/wmf_freecat122905.wmv Kinda interesting (oops, edit, I said his hardware DEP shuts it down, but not in that case)
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Ooops, I goofed. This screenshot shows what you'd see if hardware DEP shut down the exploit. I would say the screenshot is borderline NSFW btw.
 

Amused

Elite Member
Apr 14, 2001
56,009
14,556
146
Originally posted by: goku
Originally posted by: JJWalker
Originally posted by: amjohns5
Ugh, I just reformatted, and forgot my username/password for my 2 year subscription to Norton '06!!


I would look at that as a positive.
QFT
Get kaspersky, norton is garbage, absolute garbage that does sh!t for detecting viruses.

It stops this one. And, in the end, that's all the protection I need: Protection from viruses and threats that can harm me through no fault of my own.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
F-Secure reports on their blog that a new no-brainer tool has been made public so ANYONE can make their very own WMF exploit :roll:

McAfee reports that the new make-a-'sploit tool has been used to distribute a spam email containing the file HappyNewYear.jpg, which is really a .WMF. McAfee users need the 4664 DATs (available tomorrow around 10AM, at least for corporate users) and 4400 engine for detection of exploits made with the new tool. McAfee's updated info on Exploit-WMF is here.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |