Results 1 to 16 of 16

Thread: New Windows Virus With No Fix!!!

  1. #1
    Senior Member
    Join Date
    Nov 2002
    Location
    A little town called Nunyagoddamnbusiness
    Posts
    3,341
    Rep Power
    27

    Default New Windows Virus With No Fix!!!

    Copied from another source

    There is a very big virus at the moment on the internet using a flaw available in a fully patched Windows XP SP2 system (A flaw? In Windows? ORLY?) that can make a hacker take control of your computer. All you need to do to be infected is to view an infected image on a webpage. Firefox users are only HALF protected, because it will ask you if you want to save it or run it. Internet explorer users will NOT be prompted.

    It is believed that people with an AMD Athlon 64 processor MIGHT be protected against that threat (Thanks to the Malicious software protection on the chip, that Windows XP 64bit supports), but that is not proven yet.

    Microsoft has yet to provide a patch for this vulnerability.

    But here's a temporary workaround for that vulnerability available.
    Please note that I am not responsible for any damage done to your computer by this workaround.

    Workaround:



    ---------------------------------------------------------- ----------------------

    quote:
    ------------------------------------------------------------------- -------------

    1) Close any Internet Explorer window.
    2) Start, Run and write: regsvr32 -u %windir%\system32\shimgvw.dll
    This will cause that this DLL that is the problem of this vulnerability will not be registered.
    ------------------------------------------------------------------- -------------



    PLEASE NOTE THOUGH THAT THIS FIX HAS AN IMPACT!

    ---------------------------------------------------------------- ----------------

    quote:
    ------------------------------------------------------------------- -------------
    Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer. To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 2 with “regsvr32 %windir%/system32/shimgvw.dll” (without the quotation marks).
    ------------------------------------------------------------------- -------------

  2. #2
    100% Asshole FTW!!! JustinSane110™'s Avatar
    Join Date
    Apr 2005
    Location
    Chillin....
    Age
    40
    Posts
    8,098
    Rep Power
    31

    Default

    *switches from IE window to Firefox window*

  3. #3
    IA's deaf kid Deaf Pimp's Avatar
    Join Date
    Mar 2005
    Location
    In my bed...
    Age
    42
    Posts
    2,637
    Rep Power
    23

    Default

    Its a hoax.
    2005.5 Audi A4 2.0t Quattro
    APR 93/100 Chip

  4. #4
    NalleyToyota Manager ct9a gsr's Avatar
    Join Date
    Mar 2005
    Location
    Kennesaw, Ga
    Posts
    3,079
    Rep Power
    25

    Default

    There's always a fix for every virus. =]
    www.toyotaofroswell.com
    Current: '04 S2000
    Past 700whp+ Cars: '03 Z06 | '94 Supra | '03 Evo VIII | Too Many...

  5. #5
    When negotiations fail... Ruiner's Avatar
    Join Date
    Apr 2003
    Location
    Atlanta, GA
    Age
    49
    Posts
    4,631
    Rep Power
    28

    Default

    Quote Originally Posted by Deaf Pimp
    Its a hoax.
    Sure?

    Thursday, December 29, 2005

    WMF, day 2 Posted by Mikko @ 08:30 GMT Microsoft and CERT.ORG have issued bulletins on the Windows Metafile vulnerability:
    http://www.microsoft.com/technet/sec...ry/912840.mspx
    http://www.kb.cert.org/vuls/id/181038

    Microsoft's bulletin confirms that this vulnerability applies to all the main versions of Windows: Windows ME, Windows 2000, Windows XP and Windows 2003.

    They also list the REGSVR32 workaround. It's a good idea to use this while waiting for a patch. To quote Microsoft's bulletin:

    Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

    1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
    (without the quotation marks), and then click OK.


    2. A dialog box appears to confirm that the un-registration process has succeeded.
    Click OK to close the dialog box.


    Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started
    when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.


    To undo this change, re-register Shimgvw.dll by following the above steps.
    Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks).


    This workaround is better than just trying to filter files with a WMF extension. There are methods where files with other image extensions (such as BMP, GIF, PNG, JPG, JPEG, JPE, JFIF, DIB, RLE, EMF, TIF, TIFF or ICO) could be used to exploit a vulnerable machine.

    We got several questions on our note on Google Desktop yesterday. Bottom line is that if an image file with the exploit ends up to your hard drive, Google Desktop will try to index it and will execute the exploit in the process. There are several ways such a file could end up to the local drive. And this indexing-will-execute problem might happen with other desktop search engines too.

    And finally, you might want to start to filter these domains at your corporate firewalls too. Do not visit them.

    toolbarbiz[dot]biz
    toolbarsite[dot]biz
    toolbartraff[dot]biz
    toolbarurl[dot]biz
    buytoolbar[dot]biz
    buytraff[dot]biz
    iframebiz[dot]biz
    iframecash[dot]biz
    iframesite[dot]biz
    iframetraff[dot]biz
    iframeurl[dot]biz

    So far, we've only seen this exploit being used to install spyware or fake antispyware / antivirus software on the affected machines. I'm afraid we'll see real viruses using this soon.

    We've seen 57 different versions of malicious WMF files so far. We detect them all as PFV-Exploit.
    AIM: RuinerTT
    2005 Nissan Pathfinder LE

  6. #6
    Devin 5thgcelica's Avatar
    Join Date
    Mar 2005
    Location
    snellville
    Age
    40
    Posts
    17,611
    Rep Power
    39

    Default

    well..im always on firefox..and i have 64bit. so....

  7. #7
    Shine on! Nittanys1's Avatar
    Join Date
    Nov 2002
    Location
    Raleigh, NC
    Age
    43
    Posts
    14,580
    Rep Power
    39

    Default

    man I JUST had three computers F up last night and spent till 3 am installing XP on two of them...the third one is fried fried fried!!! i saw a green spark...guess I shouldn't have stuck the screw driver in there.....

    this is for SP 2 you say? I have SP 1a so should I not be in trouble? ohh and I always run firefox..ever since i had it on my mac!!!

  8. #8
    ♥Chuckster's Wifey♥ Ms Dollar's Avatar
    Join Date
    Aug 2003
    Location
    Kennesaw, Georgia
    Age
    41
    Posts
    4,260
    Rep Power
    28

    Default

    so what do i need to do? i alwasy use firefox i don't wanna f up my comp
    ~Val for President~
    ~RIP Leisa - You will be missed~


  9. #9
    Powered by AA's krindus's Avatar
    Join Date
    Mar 2005
    Location
    Charleston, SC
    Age
    42
    Posts
    202
    Rep Power
    21

    Default

    the best prevention: don't go to any unusual websites, stick with the beaten path for now.

  10. #10
    Devin 5thgcelica's Avatar
    Join Date
    Mar 2005
    Location
    snellville
    Age
    40
    Posts
    17,611
    Rep Power
    39

    Default


  11. #11
    akaDick em Down Tony PSINXS's Avatar
    Join Date
    Apr 2005
    Location
    20 side of thangs
    Age
    40
    Posts
    11,782
    Rep Power
    34

    Default

    yea i stick with my beaten ( :jerkit: ) path

  12. #12
    Devin 5thgcelica's Avatar
    Join Date
    Mar 2005
    Location
    snellville
    Age
    40
    Posts
    17,611
    Rep Power
    39

    Default

    Quote Originally Posted by PSINXS
    yea i stick with my beaten ( :jerkit: ) path

  13. #13
    akaDick em Down Tony PSINXS's Avatar
    Join Date
    Apr 2005
    Location
    20 side of thangs
    Age
    40
    Posts
    11,782
    Rep Power
    34

    Default

    thats y u gonna get the virus! lol

  14. #14
    Devin 5thgcelica's Avatar
    Join Date
    Mar 2005
    Location
    snellville
    Age
    40
    Posts
    17,611
    Rep Power
    39

    Default

    Quote Originally Posted by PSINXS
    thats y u gonna get the virus! lol
    well ur mom already has the virus!

  15. #15
    akaDick em Down Tony PSINXS's Avatar
    Join Date
    Apr 2005
    Location
    20 side of thangs
    Age
    40
    Posts
    11,782
    Rep Power
    34

    Default

    good one

  16. #16
    Rutspeed/b00b CreW BTLFED's Avatar
    Join Date
    Nov 2002
    Location
    Belview Insane Asylum
    Age
    48
    Posts
    30,776
    Rep Power
    61

    Default

    Not really.
    --RIP Leisa. Forever In Our Hearts--

    --Val for President 1979-2007--
    --RIP Val, You will be missed--

    Quote Originally Posted by HalfBaked
    Anytime I'm driving south of I-20 in the perimeter, I play spot the white driver.

    Generally I don't count past 10.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
About us
ImportAtlanta is a community of gearheads and car enthusiasts. It does not matter what kind of car or bike you drive, IA is an open community for any gearhead. Whether you're looking for advice on a performance build or posting your wheels for sale, you're welcome here!
Announcement
Welcome back to ImportAtlanta. We are currently undergoing many changes, so please report any issues you encounter with the site using the 'Contact Us' button below. Thank you!