CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Still vulnerable after install

 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
vclimber

Guest
IP: 71.83.*.*






PostPosted: Tue Jan 03, 2006 4:29 pm    Post subject: Still vulnerable after install
Reply with quote

I installed the version 1.4 fix and rebooted my machine. After reboot I ran the wfm_checker and it said that my system was still vulnerable. What could be the problem?

I am running Win XP Pro.

Back to top
ilfak

Hexblog Host


Joined: Jan 03, 2006
Posts: 21
Location: Belgium

PostPosted: Tue Jan 03, 2006 4:46 pm    Post subject:
Reply with quote

Please check question #5:

http://www.hexblog.com/security/wmffix_faq.html

How to check that the hotfix is working on my computer?

Use the checker to verify that the hotfix works. If should report that your system is invulnerable. In it reports that your system is still vulnerable, check the HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs registry key. It should contain a reference to c:\windows\system32\wmfhotfix.dll. There are some programs known to clean up this registry key. The fix will not work in this case. You should find and disable the program which cleans the registry key or uninstall the hotfix.

Back to top
View users profile Send private message Visit posters website
Corrine

Site Moderator


Joined: Aug 22, 2004
Posts: 2465

Moderators MVP

PostPosted: Wed Jan 04, 2006 2:03 am    Post subject:
Reply with quote

If you use a Real-Time Monitoring program like Lavasoft's Ad-Watch that blocks changes to your registry, you need to accept the Ad-Watch prompt when installing the WMF_Hotfix.

Further, with regard to Ad-Watch, if you have it set to "Automatic", you must turn that off first:


  1. Right click on the Ad-Watch icon in the system tray.
  2. At the bottom of the screen there will be two checkable items called "Active" and "Automatic".

    • Automatic: Suspicious activity will be blocked automatically

  3. Uncheck "Automatic"
  4. Install the WMF_Hotfix
  5. Accept the Ad-Watch prompt
  6. Shutdown/Restart the computer
  7. Run the WMF_Checker


With "event logging" turned on in Ad-Watch, you will see the following log entry:

1/1/2006 4:02:23 PM> Registry modification detected
1/1/2006 4:02:23 PM>
1/1/2006 4:02:23 PM> Root:HKEY_LOCAL_MACHINE
1/1/2006 4:02:23 PM> Key:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
1/1/2006 4:02:23 PM> Value:AppInit_DLLs
1/1/2006 4:02:23 PM> Data:
1/1/2006 4:02:23 PM> New Data:C:\WINDOWS\system32\wmfhotfix.dll
1/1/2006 4:02:23 PM>

If you are still having problems installing the WMF_Hotfix and use a different Real-Time Monitor, see http://wiki.castlecops.com/Malware_Removal:_Temporarily_Disable_Real_Time_Monitoring_Programs for instructions on temporarily disabling the program you use.


_________________
image - "Security Garden" - image
Back to top
View users profile Send private message Send email Visit posters website
Diazruanova

Lieutenant
Lieutenant


Joined: Sep 22, 2004
Posts: 162
Location: Mexico

PostPosted: Wed Jan 04, 2006 1:51 pm    Post subject:
Reply with quote

Hi,

First of all, many thanks Ilfak for all your efforts !!

Now, for my problem, I installed the patch on my W2K SP4 with all the latest updates. I have residents:

BitDefender Standard9
WinPatrol Plus (latest ver.)
ZoneAlam 4.5.594
CounterSpy 1.5.82

I installed your 1.4 fix, (no warnings from any of the residensts) and proceeded to check after a PC re-boot:
Still vulnerable.

BTW in all of this process, I NEVER received a single warning from any of the aforemntioned programs when they were active.

Uninstalled the fix, disabled all residents and prevented them to start with windows, re-boot and re-installed the fix, re-boot again and checked and I was still Vulnerable-

I checked for c:\windows\system32\wmfhotfix.dll and it is there !

Any clues?

Thanks again

Diazruanova

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 04, 2006 2:51 pm    Post subject:
Reply with quote

Hi'ya Diazruanova, iDEFENSE is claiming Win2k is not susceptible.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Diazruanova

Lieutenant
Lieutenant


Joined: Sep 22, 2004
Posts: 162
Location: Mexico

PostPosted: Wed Jan 04, 2006 4:24 pm    Post subject:
Reply with quote

Paul wrote:
Hi'ya Diazruanova, iDEFENSE is claiming Win2k is not susceptible.


Thanks Paul, now I am more confused than ever with all the contradicting information.
Do you have a link to iDEFENSE article about this issue?

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 04, 2006 4:28 pm    Post subject:
Reply with quote

I'm writing an FAQ on the front page now.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Diazruanova

Lieutenant
Lieutenant


Joined: Sep 22, 2004
Posts: 162
Location: Mexico

PostPosted: Wed Jan 04, 2006 5:42 pm    Post subject:
Reply with quote

Paul wrote:
Hi'ya Diazruanova, iDEFENSE is claiming Win2k is not susceptible.


Thanks Paul, now I am more confused than ever with all the contradicting information.
Do you have a link to iDEFENSE article about this issue?

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 04, 2006 5:45 pm    Post subject:
Reply with quote

CastleCops Link/a6445-WMF_Exploit_FAQ.html

I'll have the links in there.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Cybermage

Guest
IP: 80.126.*.*






PostPosted: Wed Jan 04, 2006 9:04 pm    Post subject:
Reply with quote

Paul wrote:
Hi'ya Diazruanova, iDEFENSE is claiming Win2k is not susceptible.


I have checked on my work some w2k machines (dutch version) but they are without patching al susceptible.
So my advise use the patch.

Back to top
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 04, 2006 10:21 pm    Post subject:
Reply with quote

New information has come in on Win2k:

CastleCops Link/a6446-DEP_not_a_total_solution_to_WMF.html

Also an FAQ on WMF:
CastleCops Link/a6445-WMF_Exploit_FAQ.html


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
vclimber

Guest
IP: 71.83.*.*






PostPosted: Thu Jan 05, 2006 8:20 am    Post subject:
Reply with quote

Diazruanova wrote:
Hi,

First of all, many thanks Ilfak for all your efforts !!

Now, for my problem, I installed the patch on my W2K SP4 with all the latest updates. I have residents:

BitDefender Standard9
WinPatrol Plus (latest ver.)
ZoneAlam 4.5.594
CounterSpy 1.5.82

I installed your 1.4 fix, (no warnings from any of the residensts) and proceeded to check after a PC re-boot:
Still vulnerable.

BTW in all of this process, I NEVER received a single warning from any of the aforemntioned programs when they were active.

Uninstalled the fix, disabled all residents and prevented them to start with windows, re-boot and re-installed the fix, re-boot again and checked and I was still Vulnerable-

I checked for c:\windows\system32\wmfhotfix.dll and it is there !

Any clues?

Thanks again

Diazruanova


I had a chat with Tech Support about BD 9 and they said that BD uses the same registry key as the WMF Hotfix. So when you reboot BD will re-write the registry entry and as a result the test program will say that you are still vunerable.

To verify I uninstalled BD 9 and tried the Hotfix again. Everything worked fine.

So basically BD's Tech Support said that you either need to uninstall the AV or go without the WMF Hotfix. They assured me that Bitdefender's AV update will protect against the exploit. I was suspect so I asked more questions and basically got hung up on.

Back to top
Diazruanova

Lieutenant
Lieutenant


Joined: Sep 22, 2004
Posts: 162
Location: Mexico

PostPosted: Thu Jan 05, 2006 1:34 pm    Post subject:
Reply with quote

vclimber wrote:


I had a chat with Tech Support about BD 9 and they said that BD uses the same registry key as the WMF Hotfix. So when you reboot BD will re-write the registry entry and as a result the test program will say that you are still vunerable.

To verify I uninstalled BD 9 and tried the Hotfix again. Everything worked fine.

So basically BD's Tech Support said that you either need to uninstall the AV or go without the WMF Hotfix. They assured me that Bitdefender's AV update will protect against the exploit. I was suspect so I asked more questions and basically got hung up on.


Yes, that is correct, the registry key shows "sockspy.dll", which belongs to BD9, but having W2K, I already checkd if there is a program that opens automatically the .wmf´s and there is none, so acording to Kaspersky, I am protected unless I install a program that reads these type of file, which I do not intend to do Wink

I am also confident about the HiVE "heuristics" that BD9 has developed, it seems to be amongst the very best on the market and it has showed it by detecting all the variants of this exploit acording to av-test.org

Thanks for your reply vclimber

Back to top
View users profile Send private message
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer