~ U P D A T E :     P A T C H   N O W.  Official patch links inside for Windows MetaFile Exploit ~~~~~~

Page 5 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

scottish144

Banned
Jul 20, 2005
835
0
0
Also try All-In-One secret maker
http://www.secretmaker.com/

It has many protection tools including an intruder blocker that block's executable content from web sites, and protects the BIOS and other parts of the system.

Edit: Also blocks banners/popups/images
 

harobikes333

Platinum Member
Sep 18, 2005
2,390
7
81
daily-page.com
so the official one from microsoft is out!?

EDIT: My computer is slow >_<

Also I tried the microsoft update and this came up!
http://img259.imageshack.us/my.php?image=010520061623309au.jpg

So ya Um a couple of days ago for some reason I had to revalidate windows because it said it detected alot of hardware changes. But I haven't changed/intalled any new hardware.

O and also do you need to unintall the unofficial hotfix before I install the official one from microsoft?

Update2: I just got that microsoft update thing. It poped up on its own:? so do I need to uninstall the unofficial one from that one website?

EDIT3: I looked at the thread title again and it said:~ REMEMBER: before patching, disable SRP if applied to Admin-class users, uninstall the UNofficial patch, and reboot! ~

Ok... well I'm on xp home with admin powers over the computer.... so I uninstall the unofficial one then I install the microsoft one. But whats this disabling SRP?????
Note: I'm waiting for help before I install
 

mchammer

Diamond Member
Dec 7, 2000
3,152
0
76
Don't worry about the SRP. That is only if you have implemented a Software Restriction Policy and you would know if you did.
 

HomeAppraiser

Platinum Member
Aug 17, 2005
2,562
1
0
"Consider not using IM until the vulnerability"

Damn, what is the safest IM right now? Yahoo, Google?

I know that P2P networks are bad, but is IRC with on auto accept still ok?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
That would be the right patch there for WinXP, yeah. Log on as an Administrator-class user and install it after removing the unofficial patch (if you used it) and rebooting.
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
Would that be Security Update for Windows XP(KB912919) ? For regular user, do I apply this patch or not?

All version of Windows are vulnerable to this patch. However, there will not be a patch for 9x and ME. If you are running automatic updates, it should pull this down automatically.

But the answer to your question is yes. All 2000, XP and 2003 (all versions and service packs for all) should install this patch.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
As a reminder, after you've installed Microsoft's patch, don't forget to re-register shimgvw.dll.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Yeah, Windows Update has it available if you want to go that route.
 

redgtxdi

Diamond Member
Jun 23, 2004
5,464
8
81
Now, forgive me if I didn't see it earlier........I read throught this monster post pretty fast, but...................


Is there a way to check if any vulnerability has been exploited already???????


Like a scan or something??

AVG doesn't seem to mention this exploit.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
The exploit delivers a payload, that's what you'd want to be most concerned about... if it did run, what did it do. Some stuff would be obvious, like if you had WinHound in your face. Some wouldn't, like keystroke loggers. You could start by 1) updating AVG, enabling every option, and running a complete scan, and 2) try some online antivirus scanners, I have a few listed on this page.

Here's a relevant article talking about which antivirus companies are doing best at detection right now: http://blog.ziffdavis.com/seltzer/archive/2006/01/04/39774.aspx If a .WMF exploit file is on your drive, it may get picked up. If the payload is on your drive, it may get picked up.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Originally posted by: mechBgon
Here's a relevant article talking about which antivirus companies are doing best at detection right now: http://blog.ziffdavis.com/seltzer/archive/2006/01/04/39774.aspx If a .WMF exploit file is on your drive, it may get picked up. If the payload is on your drive, it may get picked up.

From blog.ziffdavis.com:
Posted @ 1/5/2006 8:20 AM
I received today this up-to-date information from Trend Micro:

MOST IMPORTANT: Out of 214 WMF exploit samples received today, Trend Micro detect 214 :)
Specifically or generically; using the latest pattern (3.145.00) and engine (8.xxx) files.

Trend Micro generic detections:
- EXPL_WMF.GEN
- TROJ_NASCENE.GEN
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NASCENE.GEN

IMPORTANT: The generic pattern/detection for the WMF bug (and for other generic patterns as well) does not rely on the filename (of the file). For the WMF exploit, Trend Micro has parsing routines to identify the WMF file, and then go to the exploit part and then detect it. So even if the WMF file has been renamed, Trend Micro can still detect it.

That explains why my TrendMicro was updating so much on Wednesday and Thursday - thanks for that link, mech - I'm feeling a whole lot safer now! ;)
 

redgtxdi

Diamond Member
Jun 23, 2004
5,464
8
81
Thanks mbg..........:thumbsup:

I ran Panda on the only PC that's gone online in the last couple weeks & it appears to be clear.

Work computers................ehhh................who cares about work computers!! LOL!!! ;)
 

HomeAppraiser

Platinum Member
Aug 17, 2005
2,562
1
0
Thanks mechBgon, clicked the yellow MS Security Center shield in the system tray on my computer and updated with no pain. Had to "register windows" on my new laptop to get the update, but it worked.

On my wife's computer, no yellow shield so I used START Windows Update to get it. Now this is wierd:

My wife's Windows XP SP2 computer now has a MS SQL System Service Manager icon in her system tray after the update. From what I have read it is just a database manager, so would it be ok to delete it using Add/Remove Programs?
 

GTaudiophile

Lifer
Oct 24, 2000
29,767
33
81
Anyone know where I can get the fix for non-English versions of Windows, specifically the German version?