- May 7, 2002
- 10,371
- 762
- 126
If you have a decent firewall, (and you should), block network access to Regsvr32.exe ASAP.
http://subt0x10.blogspot.com/2016/04/bypass-application-whitelisting-script.html
In short, it is possible to use Regsvr32.exe to execute a remote url script on your system, and do all sorts of nasty stuff.
More info here http://www.bleepingcomputer.com/new...nstall-ransomware-through-jscript-installers/
And if you want a video of this exploit: http://www.youtube.com/watch?v=t8SpYn5GkHA
**A/V programs will not stop this!
http://subt0x10.blogspot.com/2016/04/bypass-application-whitelisting-script.html
In short, it is possible to use Regsvr32.exe to execute a remote url script on your system, and do all sorts of nasty stuff.
More info here http://www.bleepingcomputer.com/new...nstall-ransomware-through-jscript-installers/
And if you want a video of this exploit: http://www.youtube.com/watch?v=t8SpYn5GkHA
**A/V programs will not stop this!