[virus alert] Temporary WMF Exploit Patch Available!

A serious new remotely exploitable vulnerability has been discovered in Microsoft Windows' image processing code.

UNTIL THIS IS REPAIRED BY MICROSOFT, ANY ATTEMPTTO DISPLAY A MALICIOUS IMAGE IN WINDOWS COULDINSTALL MALICIOUS SOFTWARE INTO THE COMPUTER.

This is a so-called "0-day vulnerability" because exploits for the vulnerability appeared before any updates or patches were available. All versions of Windows from Windows 98 through ME, NT, 2000, XP, and 2003 are known to be vulnerable, and a large and rapidly growing number of malicious exploits (57 at last count) are already circulating in the wild. They are being actively used to install malware and Trojans into user's machines. Viruses and worms are expected to appear shortly. Although NOT a complete solution, Microsoft has recommended temporarily disabling the automatic display of some images by the operating system and web browser. This can be done, as detailed below, by "unregistering" the "SHIMGVW.DLL" Windows DLL. THIS IS NOT A COMPLETE SOLUTION, but it significantly lowers the risk from this vulnerability from web surfing.

Temp WMF Exploit Patch avialable here

I've used this patch myself and would say that it is safe, as I have experienced no problems with it.

#345201

Got hit with this just yesterday. It seems porn sites and celebrity pic sites are being used to spread this virus. (Don't ask what I was doing visiting those sites...I was eh,...researching). ;)

Avast! caught it and everything's still a-okay. Not sure about the other anti-virus software but Avast! has just earned its place on the computer.

#345206

Is this threat really widespread? I will disable images on the site till ms patches the problem if it is. Lots of forums are doing that. I am on a mac so I have no idea what is being effected.

#345210

Not sure how widespread it is at the moment. Might be in the best interest though I'm not sure how long it will take MS to release a fix for the issue either. The way it seems so far it isn't very high on their 'we need to fix this now' list.

#345216

I have no idea how widespread this is, but it seems to be exceptionally dangerous as it requires no user interaction in order to do it's damage - just view an infected image and bam, infected.

From what I understand, it only effects one type of graphic format -- Windows Metafile Format -- which isn't that widely used anyway. But I'm sure a clever virus writer could manipulate any sort of graphics file and exploit the backdoor in the image processing code.

#345219

for those who have kaspersky, Are all right, you have protection;)

apply one of these patchs(which ever one applies to you)

http://www.kaspersky.com/technews?id=176836515

#345225

Just update your virus scanner.

#345226

hmm, thats why im saving up for a mac mini...

#345227

I've disabled the images, I've seen many other forums take the same action.

Till microsoft addresses this offically they'll remain off. Sorry NON-Windows users but it sucks. Since this type of community relies heavily on graphical media, its best they be turned off at this time.

#345235

Don't forget to disable sigs and avatars. [Edit: Oh, and with the high volume of preview shots in the Screenshots thread, you might want to lock that for now...otherwise, people will just be uploading links to their previews.]

-NC

#345237

I hate it when us Mac users must suffer for the pc users mistakes. :P

#345268

It's not a PC users mistake though. It's the OS' authors mistakes, and OS X has it's share of exploits as well. But since it's market share is relatively low, compared to Windows based PC's, they don't attract as much attention.

#345293

i don't fully understand this virus, so... is firefox enough to protect me from this when surfing the web?

#345299

melta207@no, its an exploit on how windows manages the images... suggestion, update your AV.

its a really odd graphic file (WMF), but JPEG, PNG and such aren't affected, no need to panic

#345303

D14852001_neko, I agree... old news (internet time)

Update your virus defs.

#345304

An official patch will be out in 5 days for XP users.

Doesn't seem like this will propagate itself very quickly. So far, exploits have been focusing much more on scamming people into paying for bogus antispyware software rather than simply trying to spread itself as much as possible. I don't think this will change much before the official patch is released.

Firefox users are less vulnerable because to get infected, they must accept the download of a WMF file, and then open it. There is no mechanism to run the exploit without user interaction, unlike in (I)Explorer.

#346347

If you are using Microsofts OneCare Live, you are already protected according to MS:

Quote: "January 3, 2006 Advirsory: How to know if you are protected from the WMF vulnerability: A security vulnerability in Windows could allow malicious software to infect your computer when opening an infected graphic or a malicious Web site. Microsoft is working on a patch, but Windows OneCare is protecting you now from know viruses using this flaw."

So I guess everybody has to change to Windows Onecare bla. bla. bla... ;-) Just kidding...

#346353

Gotta love virii!

#346359