Ques on WMF exploit virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by mindnmuscl2, Jan 18, 2006.

  1. mindnmuscl2

    mindnmuscl2 Private E-2

    Hi
    This question is a preliminary step in what might be a request for help in analyzing what to do if you feel you are infected with the spreading .wmf exploit(AKA day0 exploit and other names)
    Background
    Yesterday, while using IE6(I also use firefox but was using IE6) my mcaffee went crazy saying I had been infected with the .WMFexploit. It tried to clean the file,could not but stated it was deleted.
    Later on, I shut off MCafee and ran a couple of other ancillary programs, Avast and also Ewido(I have all of these on my machine already- I know you ask not to have more than one malware protection software, but only my Mcafee and Avast loads and runs on startup). Well Avast picked up 2 instances of .wmf which it could not clean, so I quarantined them. I also tried bitdefender(ran from your site) and it stated after finding/deleting 2 instances of exploits, my machine was still infected.
    I also had just gotten all my microsoft updates for Jan downloaded AFTER my exploit awareness including the exploit patch from 1/5(I know, it is 12 days later than release but this machine is one of 2 used and has sat idle since 1/1/06)

    FINALLY MY QUESTION(S):
    -If I have put the official patch(more of a workaround from MS) into my system, rebooted it and virus removal is saying my machine is infected, does that mean I am vulnerable to exploit? I guess I am not sure if installing the patch and rebooting the machine protects me from the execution/use of the exploit or since it exists on my machine even with installed patch it will not be suppressed from being called upon to possibly do damage?

    -Do you know of a way to test vulnerability now that the patch from MS is installed?
    -I am willing to do the full "read this before posting a HJT log" but wanted to know from you guys what are your professional opinions if you think I am infected but patched?

    Sorry to bother you since I am embarrassed to ask this seeing as so much information has been around on this exploit since late DEC 05. :rolleyes:
     
  2. mindnmuscl2

    mindnmuscl2 Private E-2

    Sorry, I guess I will make my question clearer(my mistake if written incorrectly in first place)

    I applied the microsoft patch AFTER my computer virus software stated I had picked up the wmf exploit and was unable to clean it.
    Does that mean even with a patch I am vulnerable to having the exploited activated or can the MS patch prevent the exploit from running, even if it is imbedded in my machine.

    Might seem rather basic but with the patch I am not sure whether I need to do the full HJT route to remove the planted exploit.

    Thanks
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds