PubCon by Webmaster World - Speaker
Speaker bio

This blog is on the Big List of best search marketing blogs

2004 logo for Advanced Search Engine Workshops

 

Oregon Computer Consultants Association board member logo
Consultant page

  

Search Engine Marketing Alliance - PDX

  

Independent Computer Consultants Association logo

  

 

 

 

  

 

 

2005 logo for Advanced Search Engine Workshops

 

  

Windows systems are not safe today…

1st January 2006

This article is four days old, and I meant to post on it right away. All versions of Windows are affeceted, regardless of whether you’re updated with Windows patches.

One of my customers got infected already, and there was nothing I could do to fix it. By the time I got my hands on the computer, I took the hard drive out, stuck it in another machine, and could not even read the Windows directory anymore.

Watch for the large circular RED X in your tray area by the clock. If you have it, it may be too late, but CounterSpy will likely be the first to have a successful removal tool, if they haven’t already.

IMMEDIATELY DO THIS TO PROTECT YOURSELF! -
Logon as a user with full administrative rights.
Click the Windows “Start” button and select “Run…”
Enter the following (copy and paste) into the “Open” field:
regsvr32 -u shimgvw.dll
Click “OK”
and, you will receive a confirmation prompt, and your system is now safe.
* (Note that this WILL temporarily disable the “Thumbnail” view in Windows Explorer and Window’s Image and FAX viewer, because THEY ARE NOT SAFE!)

To eventually re-enable the “SHIMGVW.DLL” component once Microsoft finally patches it…
Logon as a user with full administrative rights.
“Start” button and select “Run…”
Enter the following:
regsvr32 shimgvw.dll

(Note this is the same as the one above, but no “-u” for “uninstall”)
Click “OK” to re-register the .dll file that is being exploited.
((Thanks to http://grc.com/sn/notes-020.htm for this detailed information)

Basically, you know you that should stay out of bad neighborhoods on the web, but this article will really open your eyes. Now you have proof!

Here’s the blog that I first read this news on…
Sunbelt BLOG: New exploit blows by fully patched Windows XP systems


Please leave a comment, or use one of these networks for sharing...

  • del.icio.us
  • Sphinn
  • StumbleUpon
  • Digg
  • Google
  • Technorati
  • TwitThis

2 Responses to “Windows systems are not safe today…”

  1. Ville Says:

    Or even better, use an unofficial patch that can be found, along with vulnerability detection tool, from the following URL: http://www.hexblog.com/

    The patch is un-installable via “Add or Remove Programs”.

    While not certified by Microsoft, for example F-Secure (www.f-secure.com) recommends using it until Microsoft releases a patch of their own.

     

  2. Scott Says:

    Yes Ville, you’re correct. In fact, the solution above was a stopgap measure that actually disables certain Windows functions.

    This solution is better - thanks for posting, ville, and thanks to Ilfak Guilfanov for coming up with this solution.

     

Leave a Reply

Subscribe without commenting

 Recent Posts

AddThis Social Bookmark Button
AddThis Feed Button

Recommended Affiliate Partners

Compete Search Analytics

SEOmoz.org - Learn From SEO Experts. Become an Expert.

Free SEO Tools from Aaron Wall give you a competitive advantage. Aaron wrote the worlds best SEO book, and reading that helped me get my start in search.

Best of the Web is the oldest internet directory, and guaranteed to bring you bang for your buck. It's affordable and it's highly recommended by me, Scott Hendison! I'm a paid member for life...

Park Those Unused Domains and earn some cash, instead of having them just lie around doing nothing!



 
 

Copyright 2007; Search Commander; SEO Consultant Scott Hendison; All Rights Reserved.