Duqu - the only truetype font parsing malware?

At the time of writing this, I have not become aware of any detection by Avast! of duqu. However (and the blog that I have provided a link to below states the problem more ably than I could), the real hazard is any malware that exploits the unpatched Windows bug which exposes Windows to all sorts of malicious manipulations.

http://blogs.computerworld.com/19247/why_duqu_is_more_dangerous_than_most_people_think

Hi hake,

Apparently you are not aware what was posted here: http://forum.avast.com/index.php?topic=37542.msg705869#msg705869
Another free detector toolkit can be found here: http://www.crysys.hu/duqudetector.html
link source: Budapest University of Technology and Economics - tool developer = CrySyS

polonus

http://forum.avast.com/index.php?topic=52252.msg705517#msg705517

Hi Asyn,

I installed the hotfix, see http://support.microsoft.com/kb/2532445 and will remove it when the new official patch will be in. I did not have any issues since I have Microsoft FixIt Center,

polonus

Guess you mean this one: http://support.microsoft.com/kb/2639658 :wink:
Also read here: http://www.avast.com/zero-day-exploit-reports

From the hotfix

Prerequisites
To apply this hotfix, you must be running one of the following operating systems:
•Windows 7
•Windows 7 Service Pack 1 (SP1)
•Windows Server 2008 R2
•Windows Server 2008 R2 Service Pack 1 (SP1)

http://www.nsslabs.com/blog/2011/11/duqu-analysis-and-detection-tool.html

Note: DuQu installs a keylogger in order to record keystrokes and collect other system information.

Something interesting here:
DuQu is NOT self-replicating

Kenny, pol posted the wrong hotfix, see my reply above…! :wink:

It still only applies to Windows 7 systems though.

Hi YoKenny,

@Asyn, Thanks for that right hotfix, the other one is also a gaping developing mistake that can be abused. So W7 owners should fix both issues.

@YoKenny and @Left123, Thanks for the additional info. The clever DuQu malcreants sure know what vulnerability windows to open and what won’t get patched…they make “all the skeletons that are out there in the MS cupboard” rattle to their own advance,

polonus

No, it doesn’t.
Read here: http://support.microsoft.com/kb/2639658

NP, pal. :slight_smile: