WMF Vulnerability Avast! Official Confirmation

Does Avast include signature for this exploit?

I thing Avast is taking a very low profile in this matter.

I know there is a thread in Virus-forum with different suggestions, but I think Avast should give an official confirmation that Avast users are safe! or not?

Regards
Hannibal Lecter

As far as I know avast! is one of the first AVs that release a signature of this exploit.

http://forum.avast.com/index.php?topic=18295.0

TAP:

Could you please quote the official answer to my question in that Thread?

Regards
Hannibal L

TAP:

Your suggestion to include *.wmf in the URL block list is good but according to MS Security Advisory 912840 it is possible for the files to disguise as eg gif or another picture format.

Hannibal L

See my post here (but I can’t confirm if it’s safe or not)
http://forum.avast.com/index.php?topic=18295.msg155892#msg155892

I can answer your question (first question) about the signature of this exploit, But I can’t give an official confirmation that avast users are safe. vlk or other Alwil staff are the right person to do so.

Vlk said in the thread I mentioned that Avast were working on it but that it would take some time to produce the signature.

What is the name Avast uses, then I can check in viruslist on Avast site.
The last defs you can read there are from 28.12.

The defs from 29.12 are not specified.

We really need some official clarification.

Hannibal Lecter

AFAIK, Avast! uses “Win32:Exdown [Trj]” for the exploit.
It has been added 28.12.

As Sgt.Schumann said and I have the sample of this exploit.

Thank you all for convincing me! :slight_smile:

Hannibal Lecter
“Looking forward to my new year meal”

The quote from Vlk was before the update containing the signature for the exploit was deployed.

Hi Hlecter :D,

If I remember corectly, You and I recently had a nice chat at the aSquared Support Forum. You offered help about signature backup and while waiting for moderators to return we talked about casual stuff, remember? ;D

I’m so glad that you’re a happy avast user! Well, if you need a chat again, please don’t hesitate to return to one of the best forums on this matter :wink:

I’ll say once more: “Have a pleasant meal” 8)

I just go to some website that contains this exploit but avast! Web Shield protects me very well.

Hi Zagor :slight_smile:

Yes, we meet again. The world isn`t that big, is it.

I have been a happy Avast user for a very long time, but not very active on this forum as you can see from my number of counts. Never needed help, I guess ;).

But one thing I will say for sure: we will meet again. :wink:

Have a nice day (and a happy new year) if we don`t meet again THIS YEAR!

TAP:
Could you please PM me the address of said website? Thank you! ;D

Edit: I suppose you have removed *.wmf from URL blocking now, should not be necessary?

Have a nice day (and a happy new year)

You too! :wink:

Is AVAST’s signature for the current version of WMF that was found a couple of days ago as reported here? Apparently this is the second incarnation of WMF and is pretty bad.

http://sunbeltblog.blogspot.com/2005/12/new-exploit-blows-by-fully-patched.html

Welcome anyway… If you could, just come here to help the others 8)

Tech:

“Never needed help” was of course a joke. :slight_smile:

But to be serious:
Thanks for welcome. We all need help sometimes.

For me Avast has been pretty much “set and forget” for a couple of years.

I am a bit disappointed about Avast not informing more about the serious threat
mentioned in this thread. :cry:

As you see from the thread it was much digging to find out if this exploit was covered by Avast. I found the answer important, especially before I got the workaround from MS.

I have read bout this virus a few days ago and i instantly set the “webshield” with a block on wmf files.
So I guess it should be OK for now,…thank god for the webshield function!

Funny but I hardly use these kinds of files (as a graphical designer). Some wmf files can be vectorized art,…so at work we sometimes have them when we download logo’s/images from a CD-ROM.

As you see, virus/malware/spyware writers become more and more clever!
The video that Vlk set on the forum was a very good illustrator what to expect!

greetings

John

Why if VPS was updated and avast is protecting you…
On contrary, as you can see, with WebShield you’re more protected that other antivirus that does not offer this shield of protection.

That`s fine, but then it would be natural for Avast as my antivirusprovider to INFORM about this. :-[

Webshield is ok, but URL BLOCKLIST is EMPTY by default… >:(

Microsoft informed about wmf-files, not Avast. :frowning:

It is a question of information. Look at F-SECURES START PAGE ;D

I like Avast, but good things can also get better. :wink:

Hannibal Lecter