New Windows exploit found - can infect your computer just by viewing an image

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Link here:

http://www.securityfocus.com/brief/89

Basicly it uses files with the Windows Metafile format to infect a computer. All you have to do is view a webpage with the image on it or access an infected image on your computer. For IE users, it will infect them automatically, since IE displays the images nativly. Firefox will not display the image but will cache it, so if you mouseover/click/open the image from the cache, you will be infected.

There are reports of it downloading spyware, trojans, etc. There is no fix available from MS at this time.

Virus scanners should be updating themselves to detect this threat. NOD32 trial version already can, so if you don't have a virus scanner, get it here:

http://www.eset.com/download/trial.htm

Other things you can do are to avoid shady websites that might exploit this (although there are reports of it showing up on ebay auctions and myspace pages). Run an alternative browser, such as Firefox or Opera. Turn off programs such as Google's Desktop search, that index files on your computer. An infected WMF file just being index by such programs is enough to infect your PC. Avoid image searching. Update windows regularly. This one is bad enough that MS should patch it pretty quick - but you never know.

I apologize if this is a repost, I searched for a bit before posting this here. I know this should be in software, but OT gets WAY more traffic and people need to know about this.

Edit: Link with more info:

http://forums.anandtech.com/messageview.aspx?catid=38&threadid=1770474
 

Safeway

Lifer
Jun 22, 2004
12,081
9
81
Wow :Q

Edit: I'm glad Anandtech doesn't offer direct image viewing on posts :laugh:
 

dug777

Lifer
Oct 13, 2004
24,778
4
0
Originally posted by: Phil
Good to know.

Hey Amused, here's the first virus that can infect you without your consent!

maybe it can tell you're high?
 

SLCentral

Diamond Member
Feb 13, 2003
3,542
0
71
My brother got this yesterday, I think. Totally f-ed up his PC, and he had to format. Even a clean with SpyBot, Adaware, and Norton wouldn't fix it :\. Of course, this was before I heard stories about this attack, so I told him to go ahead and format before I learned about the NOD32 fix.
 

Aquila76

Diamond Member
Apr 11, 2004
3,549
1
0
www.facebook.com
I'm surprised Nik hasn't said "Wrong Forum" yet. :evil:

j/k This should be in EVERY forum to spread the message. Kinda like a Tornado Warning System.
 

trinketsummoner

Senior member
Aug 24, 2004
695
1
81
Originally posted by: SLCentral
My brother got this yesterday, I think. Totally f-ed up his PC, and he had to format. Even a clean with SpyBot, Adaware, and Norton wouldn't fix it :\. Of course, this was before I heard stories about this attack, so I told him to go ahead and format before I learned about the NOD32 fix.

So what pr0n site did he visit?
 

SLCentral

Diamond Member
Feb 13, 2003
3,542
0
71
Originally posted by: trinketsummoner
Originally posted by: SLCentral
My brother got this yesterday, I think. Totally f-ed up his PC, and he had to format. Even a clean with SpyBot, Adaware, and Norton wouldn't fix it :\. Of course, this was before I heard stories about this attack, so I told him to go ahead and format before I learned about the NOD32 fix.

So what pr0n site did he visit?

. He claims he was just sitting at his desk not even using his computer when all sorts of popups came up.
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Originally posted by: Aquila76
I'm surprised Nik hasn't said "Wrong Forum" yet. :evil:

j/k This should be in EVERY forum to spread the message. Kinda like a Tornado Warning System.
I PM'ed the mods about this thread and asked them to sticky it if you wasn't a repost. Hopefully they'll sticky threads about it in the other forums too.

Edit: Doesn't have to be a porn site. Any site that allows direct-linking of images can have it. Forums where signatures with images allowed are a risk. Over at the SomethingAwful forums, someone had a 1x1 pixel image in his signature with the virus (he was found out and permabanned).

People were even saying that auctions for xbox 360's on eBay had infected images in them.
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76

apinomus

Senior member
Dec 14, 2005
394
0
0
Yeah our IT people said there was a registry fix for this. I'll poll them on what it is...
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Originally posted by: Chadder007
Mcafee caught something on my yesterday called Accoona?
No offical name yet since it's just an exploit. MS is calling it the "Windows Metafile Vulnerbility".

F-Secure has their lab blog updated with some info here:

http://www.f-secure.com/weblog/

Including a way to unregister Windows Picture and Fax Viewer - which they say is a good idea until the patch comes down.
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
Originally posted by: apinomus
Yeah our IT people said there was a registry fix for this. I'll poll them on what it is...
It's probably disabling the vulnerable DLL. I did that and was glad I did, I had a WMF come up later that night.
 

apinomus

Senior member
Dec 14, 2005
394
0
0
From the f-secure weblog:

Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.

2. A dialog box appears to confirm that the un-registration process has succeeded.
Click OK to close the dialog box.

Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started
when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps.
Replace the text in Step 1 with ?regsvr32 %windir%\system32\shimgvw.dll? (without the quotation marks).

This workaround is better than just trying to filter files with a WMF extension. There are methods where files with other image extensions (such as BMP, GIF, PNG, JPG, JPEG, JPE, JFIF, DIB, RLE, EMF, TIF, TIFF or ICO) could be used to exploit a vulnerable machine.

This worked pretty quick for me and sounds like a good fix, since I don't use that annoying app anyway. IrfanView FTW
 

apinomus

Senior member
Dec 14, 2005
394
0
0
Originally posted by: SampSon
This is the same type of exploit that has been used for over a year now.

It's probably something different, otherwise large AV companies wouldn't be making such a fuss over it.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |