
|
|
|
Windows ME, Windows 2000, Windows XP
and Windows 2003 are currently vulnerable to a new WMF exploit with
no current patch available as of the 29th December 2005.
Please read this article to discover
more about the threat and how to protect yourself!
|
UPDATE! There is now a security patch available for this threat.
More here:
http://www.updatexp.com/kb912919.html
So What Is This WMF Threat...
WMF stands for Windows Metafile Format. This is a
graphics file format used to exchange graphics information between
Microsoft Windows applications.
HOWEVER we are
currently seeing in the last few days websites (and some email)
using a vulnerability in this file format to infect users computers!
As of writing this
article there in NO SECURITY PATCH available from
Microsoft...
Please note that this
is NOT the same wmf exploit detailed at:
http://www.microsoft.com/technet/security/bulletin/MS05-053.mspx
How can I get Infected?
When you visit a Web site that contains a
specially crafted Windows Metafile (.WMF) image you can become
infected. Now it is important to note that an attacker would have to
persuade you visit their Web site and this is typically done by
getting you to click a link that takes you to the dangerous Web
site!
SPAM email is a great
example of this in action...
SO NEVER CLICK A
LINK IN AN EMAIL YOU WERE NOT EXPECTING OR DO NOT TRUST!
Some known websites
with the ability to infect you are:
www.toolbarbiz.biz
www.toolbarsite.biz
www.toolbartraff.biz
www.toolbarurl.biz
www.buytoolbar.biz
www.buytraff.biz
www.iframebiz.biz
www.iframecash.biz
www.iframesite.biz
www.iframetraff.biz
www.iframeurl.biz
www.crackz.ws
www.unionseek.com
www.tfcco.com
www.Iframeurl.biz
www.beehappyy.biz
Any application that
automatically displays a .WMF image will cause the user’s machines
to get infected. This includes older versions of Firefox, current
versions of Opera, Outlook and all current version of Internet
Explorer on all versions of Windows.
This is NASTY - Be Careful!
So What Can Happen To My Computer?
...as of writing this article the online community is
seeing this wmf exploit being used to spread TROJANS that install
Spyware or fake AntiSpyware / fake AntiVirus software on a Windows
computer.
BUT
you can bet in a day or two we will see viruses being spread this
way!
Some of the software installed as part of the
infection may produce a FAKE security warning in order to make a
YOU go to a website the attacker wants you to visit!
Here are a couple of
examples of the fake security warnings:


So
What Can You Do To Protect Yourself?
Here are my recommendations:
1) Make sure you have an up to
date AntiVirus program on your computer! If you have none then try
the FREE AVG software
http://free.grisoft.com
2) Make sure you are using an
up to date Anti Spyware solution on your computer! If you have none
try the free 30 day trial of Spy Sweeper
www.free-trial-of-spy-sweeper.com OR
http://www.updatexp.net/spysweepertrial45.exe
3) Keep Windows up to date by
keeping Windows Update turned on to automatically receive security
updates from Microsoft! Please read my article:
http://www.updatexp.com/windows-automatic-updates.html
4)
8)
TAKE THIS WARNING SERIOUSLY and simply do not click on an email or
website link from an untrusted source!
-----------------------------------------------------------------------