Back to Forums








View Full Version : First JPEG Virus Posted To Usenet


egghead
September 28th, 2004, 05:37 AM
Posted by timothy (http://www.monkey.org/%7Etimothy/) on Monday September 27, @10:12PM
from the one-neck-to-wring dept.
Shawn (shawn@easynews.com) writes "This could possibly be the worst viruses yet! Earlier this month Microsoft announced (http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx) a problem in their GDI driver that processes the way JPEG images are displayed. Someone has finally posted an exploit to Usenet. Easynews, a premium Usenet provider, found the virus Sunday afternoon. Up-to-date information about how we found it and what it does is located at www.easynews.com/virus.txt (http://www.easynews.com/virus.txt). When this picture is viewed it installs remote management software (winvnc and radmin) and will connect to irc."

source:http://slashdot.org/article.pl?sid=04/09/27/2319222


everyone should read what easynews has found..
this is scary and the exploit works if you change file to .bmp, .ping, .tiff, .gif etc....

egghead

rohitk89
September 28th, 2004, 06:08 AM
i have avg 7.0 will it protect me from the virus?

egghead
September 28th, 2004, 06:15 AM
this is not a virus but an exploit.

I do not know if avg will alert you to it but this needs to be fixed by microsoft

update you xp now

many keyloggers and commercial spy programs or monitoring programs work off exploits to the os and as a result you are never alerted/cannot be detected by antivirus companies and you are monitored or hacked silently .

more info here,
http://www.theinquirer.net/?article=18656

rohitk89
September 28th, 2004, 06:25 AM
ok...thanks

ankit
September 29th, 2004, 03:22 AM
Dude rohit why ur giving name of ur ****ing web.....?

rohitk89
September 29th, 2004, 04:42 AM
sorry?
i was unable to get you...are u saying that it's exploitable because of it being mentioned in that manner?...

Conan
September 29th, 2004, 10:50 AM
Dude rohit why ur giving name of ur ****ing web.....?

Please address other members in a proper manner or face my WRATH! :smash:

rohitk89
September 29th, 2004, 12:53 PM
Please address other members in a proper manner or face my WRATH! :smash:

my hero! :D (really, i did get kinda pissed)

rik
September 29th, 2004, 13:29 PM
That is a scary read...Thanks egghead

phishhead
September 29th, 2004, 14:49 PM
my hero! :D (really, i did get kinda pissed)

and thats why conan took care of it...flaming is not tolerated here...and will be delt with accordingly. :cool:

lynchknot
September 29th, 2004, 15:10 PM
http://www.virustotal.com/flash/index_en.html

BitDefender 7 09.28.2004 -
ClamWin devel-20040822 09.28.2004 -
F-Prot 3.15a 09.28.2004 -
Kaspersky 4.0.2.24 09.28.2004 Exploit.IE.Crashsos
McAfee 4395 09.28.2004 -
NOD32v2 1.88 09.28.2004 Exploit.IE.Crashsos
Norman 5.70.10 09.28.2004 -
Panda 7.02.00 09.28.2004 -
Sybari 7.5.1314 09.28.2004 -
Symantec 8 09.27.2004 -
TrendMicro 7.1 09.26.2004 - :)