shadow
Home | Support | Contact Us
shadow
   
NEWS

New Microsoft Security Alert!!!!

A vulnerability in Microsoft Video ActiveX control could allow a hacker to remotely control a user’s PC without any user interaction.

2009-07-07

Jul6
5:36 pm (UTC-7)   |   by Roland Dela Paz (Threat Response Engineer)

Earlier today, TrendLabs has been alerted of a zero-day exploit in the Microsoft Video streaming ActiveX control MsVidCtl. Around 967 Chinese websites are reported to be infected by a malicious script that leads users to successive site redirections and lands them to download a .JPG file containing the exploit. Trend Micro detects it as JS_DLOADER.BD. Here’s a screenshot of the encrypted exploit code:

Click for larger view

The shellcode of the exploit is XOR encrypted. Below is the screenshot of the decrypted shellcode:

Click for larger view

Microsoft already released a security advisory regarding this vulnerability. More information can be found in the following page:

Upon successful exploitation, the script downloads another malware detected as WORM_KILLAV.AI. This malware disables and terminates antivirus software processes, and drops other malware on the affected system.

As of this writing, all domains are blocked already by Smart Protection Network. Furthermore, OfficeScan users with Intrusion Defense Firewall plugin installed are protected from this threat if they have updated to the latest filters (IDF09021).

 


http://blog.trendmicro.com/zero-day-microsoft-directshow-mpeg2tunerequest-exploit-leads-to-killav-malware/#ixzz0Kct8Gb2m&D

 

Solutions | News | Support | Partners | About Aperio | Contact Us
All Content Copyright 1006, 2007, 2008 Aperio, Inc. | www.Aperio.cc | Privacy Policy
 
botleft footer botright