CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

Win98SE will not install the WMF HotFix . .
Goto page 1, 2  Next
 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 3:19 pm    Post subject: Win98SE will not install the WMF HotFix . .
Reply with quote

I have downloaded the HotFix from GRCdotCom and from HexBlog for Ilfak Guilfanov, the newer Silent version and it will NOT install either.


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
ilfak

Hexblog Host


Joined: Jan 03, 2006
Posts: 21
Location: Belgium

PostPosted: Tue Jan 03, 2006 3:28 pm    Post subject:
Reply with quote

This is correct, win98SE is not supported. Sorry.

Back to top
View users profile Send private message Visit posters website
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 3:50 pm    Post subject: Win98SE . .
Reply with quote

[quote="ilfak"]This is correct, win98SE is not supported. Sorry.[/quote]

'ilfak',

Thank you for confirming this, on Mr. Gibson's website there is reference to Win98 through all updates to 2003 and I was checking to see if my system was supported.

Not a problem with me, as I will just disable the dll files as needed until somethingy is done by MicroBarf er MicroSoft.

Again, thank you,


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 3:55 pm    Post subject:
Reply with quote

Take a look at this from SANS: http://handlers.dshield.org/jullrich/wmffaq.html

Excerpts:

Quote:
The WMF vulnerability uses images (WMF images) to execute arbitrary code. It will execute just by viewing the image. In most cases, you don't have click anything. Even images stored on your system may cause the exploit to be triggered if it is indexed by some indexing software. Viewing a directory in Explorer with 'Icon size' images will cause the exploit to be triggered as well. Microsoft announced that an official patch will not be available before January 10th 2006 (next regular update cycle).

Note: If you're still running on Win98/ME, this is a watershed moment: we believe (untested) that your system is vulnerable and there will be no patch from MS. Your mitigation options are very limited. You really need to upgrade.


My online machine is Win98se. I shall be "upgrading" to Linux Suse. I've had enough of MS weaknesses. I need a fully stable and dependable OS and Suse is most assuredly that.

Other than that, we shall have to wait for the antivirus vendors to provide a detection and removal method since it is being distributed as a virus.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 4:00 pm    Post subject:
Reply with quote

'Prince_Serendip'

Thank you for this input, I am stuck here on this Win98SE system from now on. When retired and on a fixed income your options are very limited. Maybe when I finally HIT the LOTTO there will be some changes available to me. Until then . .


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 4:09 pm    Post subject:
Reply with quote

Linux Suse is freeware. You might need to check with a hardware specialist to see if you can use it on your equipment? (see our Hardware Forum)

If you have a CD burner you can download it yourself. If not, the CDs are cheap. My income is screwed from Christmas so I don't have much option. I may have to load it on my old tower but I had wanted to get a new one.

Linux CD Dot Org

Hope this helps you?


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 4:12 pm    Post subject:
Reply with quote

'Prince_Serendip'

Hey, anythingy helps me, when you are HELPLESS any will be of some.

Thanx,


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 4:25 pm    Post subject:
Reply with quote

You are most welcome. Now I need to backup all of my important files, get instructions on how to clean MS off my box, check my old hardware and load the new OS.

It's a good idea to read up on Suse before taking the plunge? Wink

Novell sells Suse but as I said it's freeware. They are selling the package all setup but they have some good help pages. Here's one:

Novell Suse Hardware Compatibility List

Suse Linux Info

That will get you started. HTH?


Larry Thumbs Up


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 4:28 pm    Post subject:
Reply with quote

'Prince_Serendip'

I have downloaded a checker for WMF and it shows my system to invulnerable at this time. I have not done anythingy to make it so, I have done searches for the shimgvw.dll file and GDI32.dll finding only the GDI version. Is that OK?

I await your return,


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 4:39 pm    Post subject:
Reply with quote

Not invulnerable. This exploit affects all Windows versions all the way back to 3.0! Shocked Shocked Shocked Evil or Very Mad

See the info here from F-Secure: http://www.f-secure.com/weblog/archives/archive-012006.html#00000761


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 5:04 pm    Post subject:
Reply with quote

New Information from Larry Seltzer at Ziff-Davis: http://blog.ziffdavis.com/seltzer/archive/2006/01/03/39684.aspx

It may well be that Win98/Me are invulnerable to this exploit? They have been testing it. Keep fingers crossed.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17155

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Jan 03, 2006 5:46 pm    Post subject:
Reply with quote

With the info provided there, I can start breathing a little easier again. I am still switching to the Suse but now I have more time to put it in place. Thumbs Up

See this topic for more: CastleCops Link/t143179-WMF_Exploit_Major_Revision_In_Vulnerable_System_List.html


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 10:01 pm    Post subject: Breathing a little better . . .
Reply with quote

[quote="Prince_Serendip"]With the info provided there, I can start breathing a little easier again. I am still switching to the Suse but now I have more time to put it in place. :tup:

See this topic for more: CastleCops Link/t143179-WMF_Exploit_Major_Revision_In_Vulnerable_System_List.html[/quote]

"Princely_Serendip,"

Maybe that is why I cannot find the shimgvw.dll file on my system nor can rename the GDI32.dll file, WindBlows will not load without that file.

Yes, you can stop holding your breath and take your time to complete the task with as few ERRORS as possible.

Let me know how it goes. I have Linux RedHat v8 but it will not load on my system, even though it was there at one time. My system is just too old for this new fangled/dangled software. That is why I must remain on Win98SEPlus98 v4.10.2222A.

Maybe some day . . . far far far far away there just may happen to be a newer system that just may take me out of this problem area.


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 166


PostPosted: Tue Jan 03, 2006 11:03 pm    Post subject: WMF problems . . .
Reply with quote

Greetings ALL from LeonSprings, Texas USofA,

Before i leave here and only return when there is a problem, go to http://blog.ziffdavis.com/seltzer/archive/2006/01/03/39684.aspx and read down the info posted on this BLOG and see the discussions and feedback on this very problem. Thank you to IfanView for having a good viewer that will show these images, but; we of Win98SE are NOT part of the group with this problem.

Thank you to all from CastleCops for finding this info and SHARING.


_________________
TIA, CU L8R, > 'Lkkb' <IP-III 850MHz, 512Mg, XP HE v5.1/SP-2, IE v7.0, FireFox v2.0.0.14/ wPasswordMaker v1.7.2, NoScript v1.6.5;CFP v3.0.25.378, SBS&Dv1.5, AntiVir v8.01.xxx
Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Jan 03, 2006 11:07 pm    Post subject:
Reply with quote

Our pleasure, I'm about to update the front page news and the banner in the forums with the latest data.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer