Author Topic: Another 0-day exploit on the loose  (Read 2047 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33939
  • malware fighter
Another 0-day exploit on the loose
« on: September 26, 2006, 02:00:45 PM »
Hi malware fighters,

Another variation of the zero-day exploit found up Sept 14th last seems on the loose, infecting XP SP2 computers, the browser crashes, but the malware is succesfully installed:
http://sunbeltblog.blogspot.com/2006/09/another-zero-day-on-loose-keyframe.html
A mitigation is given here too.

In a hjt log the malware may look anything like:
O21 - SSODL: rjgoitr - {CDEFEE3D-EDCB-4226-931B-90E184C11CAC} - C:\WINDOWS\SYSTEM\hehesox.dll

polonus
« Last Edit: September 26, 2006, 02:04:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Another 0-day exploit on the loose
« Reply #1 on: September 26, 2006, 02:05:26 PM »
I think we're talking about the same thing here:

http://forum.avast.com/index.php?topic=23619.0

 ;)
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog