scannow sfc


Site
Search
Tool

 POPULAR XP NEWSLETTER

Claim Your FREE Guides!

-------------------
RSS Feeds:

What's RSS?

Newsletter:

Free RSS Newsletter about Windows XP

RSS Text Link

New Articles:

Free RSS Newsletter about Windows XP

RSS Text Link

 

POPULAR ARTICLES

 

COMMON ERRORS

 

DIGITAL
MEDIA

 
 

TRIAL SOFTWARE
 

 

Site
Search
Tool

WMF Exploit - Warning!

Published By Marc Liron - Microsoft MVP


Windows XP WMF Exploit..... (Updated 12th January 2005)

  wmf exploit
 

 

Windows ME, Windows 2000, Windows XP and Windows 2003 are currently vulnerable to a new WMF exploit with no current patch available as of the 29th December 2005.

Please read this article to discover more about the threat and how to protect yourself!

 

UPDATE! There is now a security patch available for this threat. More here:

http://www.updatexp.com/kb912919.html

 

So What Is This WMF Threat...

WMF stands for Windows Metafile Format. This is a graphics file format used to exchange graphics information between Microsoft Windows applications.

HOWEVER we are currently seeing in the last few days websites (and some email) using a vulnerability in this file format to infect users computers!

As of writing this article there in NO SECURITY PATCH available from Microsoft...

Please note that this is NOT the same wmf exploit detailed at: http://www.microsoft.com/technet/security/bulletin/MS05-053.mspx

How can I get Infected?

When you visit  a Web site that contains a specially crafted Windows Metafile (.WMF) image you can become infected. Now it is important to note that an attacker would have to persuade you visit their Web site and this is typically done by getting you to click a link that takes you to the dangerous Web site!

SPAM email is a great example of this in action...

SO NEVER CLICK A LINK IN AN EMAIL YOU WERE NOT EXPECTING OR DO NOT TRUST!

Some known websites with the ability to infect you are:

www.toolbarbiz.biz
www.toolbarsite.biz
www.toolbartraff.biz
www.toolbarurl.biz
www.buytoolbar.biz
www.buytraff.biz
www.iframebiz.biz
www.iframecash.biz
www.iframesite.biz
www.iframetraff.biz
www.iframeurl.biz
www.crackz.ws
www.unionseek.com
www.tfcco.com
www.Iframeurl.biz
www.beehappyy.biz

Any application that automatically displays a .WMF image will cause the user’s machines to get infected. This includes older versions of Firefox, current versions of Opera, Outlook and all current version of Internet Explorer on all versions of Windows.

This is NASTY - Be Careful!

So What Can Happen To My Computer?

...as of writing this article the online community is seeing this wmf exploit being used to spread TROJANS that install Spyware or fake AntiSpyware / fake AntiVirus software on a Windows computer.

BUT you can bet in a day or two we will see viruses being spread this way!

Some of the software installed as part of the infection may produce a FAKE security warning in order to make a YOU go to a website the attacker wants you to visit!

Here are a couple of examples of the fake security warnings:
 

wmf exploit

wmf exploit


 

So What Can You Do To Protect Yourself?

Here are my recommendations:

1) Make sure you have an up to date AntiVirus program on your computer! If you have none then try the FREE AVG software http://free.grisoft.com

2) Make sure you are using an up to date Anti Spyware solution on your computer! If you have none try the free 30 day trial of Spy Sweeper www.free-trial-of-spy-sweeper.com OR http://www.updatexp.net/spysweepertrial45.exe

3) Keep Windows up to date by keeping Windows Update turned on to automatically receive security updates from Microsoft! Please read my article: http://www.updatexp.com/windows-automatic-updates.html

4) Disable indexing of media files in Google Desktop OR remove Google Desktop on your Windows computer until there is a security patch available for this exploit from Microsoft.... (If an image file with the wmf exploit ends up to your hard drive, Google Desktop will try to index it and will execute the exploit in the process! Not something I want to see happen on your computer...)

5) Un-register the Windows Picture and Fax Viewer on your computer (Shimgvw.dll)

Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.

A dialog box appears to confirm that the un-registration process has succeeded.
OK to close the dialog box.

Impact of this Workaround: The Windows Picture and Fax Viewer will no longer be started when you click on a link to an image type that is associated with the Windows Picture and Fax Viewer. This can prevent a wmf exploit attack on your computer! ALSO thumbnails will no longer work until you re-register the file....

To undo this change, re-register Shimgvw.dll by following the above steps.
Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks). Do this AFTER installing any forth coming Microsoft Security patch...

If that fails try: clicking Start, then Run, then enter the following command:

regsvr32 /u shimgvw.dll

To re-enable the same DLL, click Start, then Run, then enter the following command:

regsvr32 shimgvw.dll

6) (Advanced Users Only) The same effect may be obtained with a registry change. In the Regedit program go to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes
\SystemFileAssociations\image
\ShellEx\ContextMenuHandlers
\ShellImagePreview


Then delete the default value. To re-enable the feature, go to the same key and set the default value as a REG_SZ to "{e84fda7c-1d6a-45f6-b725-cb260c236066}".
 

7) Turn on Data Execution Prevention (DEP) for ALL Windows programs and services UNTIL a security patch for this wmf exploit is issued by Microsoft.... Read my article here for more information on how to do this: http://www.updatexp.com/data-execution-prevention.html

If DEP is greyed out on your computer this means DEP has been disabled in the boot.ini file, see the end of this article for more info: http://www.updatexp.com/0xC0000005.html

8) TAKE THIS WARNING SERIOUSLY and simply do not click on an email or website link from an untrusted source!

-----------------------------------------------------------------------

wmp

 

 

Enjoy the rest of site and remember if you have a query or a comment to make then drop me a line at the Contact Page and remember to sign up for my free newsletter Subscribe Now!.

 

wmp
The Windows Media Player DVD XPack

The DVD XPack instantly adds DVD playback to
Windows Media Player 9 & 10. It Installs the
same theatre-quality video and audio decoders
proven by over 45 million users of WinDVD -
the world's leading software DVD player.

Why Use It? BECAUSE:

It's FAST, cheap, no-fuss use and Microsoft approved!

www.watch-dvds-in-wmp.com

I have been using this plug-in for several years now
and have never had a problem with it!

NB - Link not working correctly in your browser?
Click here: The InterVideo DVDXPack

-----------------------------------------------------------------------------------------

Finally a quality XP Newsletter!

FACT: There are dozens of Windows XP newsletters - BUT this one is different!

 
First name

 
E-mail address

 
Subscribe                 Unsubscribe
 
I HATE SPAM AS MUCH AS YOU DO!
That is why you'll get none from me...
 
 
NB - You will need to click the special link in the confirmation  email I send you to activate YOUR subscription and receive the newsletter!
 
This is called double opt-in and is an anti spam measure...
 
 

Find out more here: XP Newsletter

Kind Regards

Marc Liron - Bio
Microsoft Digital Media MVP
Your Guide to using Windows XP
A Unique Windows XP Newsletter? Sign Up Now!
- Make sure you get your FREE tips and advice...

 

The views on this website are my own and NOT that of Microsoft!
I am not responsible for the content of any sites linked to.
ALL Trademarks are freely acknowledged
ALL information is provided "
As Is"

This page was last updated 29th December 2005

Home Page | Privacy Policy | Site Search | Contact Me

© Marc Liron 2003 - 2006 www.marcliron.com
Registered with the US Copyright Office - No. TX 6-059-023