![]() |
|
#1
|
||||
|
||||
|
http://www.nsclean.com/psc-htas.html
__________________
Regards, Pieter Itīs nice to be important, but itīs more important to be nice. It's human to make mistakes. It's even more so to blame the computer for it. |
|
#2
|
||||
|
||||
|
I suppose those activities will be stopped by Wormguard
![]() Dolf
__________________
Idealism is what precedes experience; cynicism is what follows.
Of those who say nothing, few are silent.
|
|
#3
|
||||
|
||||
|
Hi Dollefie,
The HTA scripts can be stopped by checking them in WormGuard or ScriptSentry or any other program that is able to intercept the call made by the .hta extension. Regards, Pieter
__________________
Regards, Pieter Itīs nice to be important, but itīs more important to be nice. It's human to make mistakes. It's even more so to blame the computer for it. |
|
#4
|
||||
|
||||
|
If anyone has a direct link to somewhere that I can get infected with this thing, please email or PM it to me.
I want to see an alert from WormGuard on it so I can put up a screenshot. Thanks. Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis |
|
#5
|
||||
|
||||
|
Hi Pete,
Check your IM. ![]() Regards, Pieter
__________________
Regards, Pieter Itīs nice to be important, but itīs more important to be nice. It's human to make mistakes. It's even more so to blame the computer for it. |
|
#6
|
||||
|
||||
|
Code:
save as htanotepad.hta
__________________
Idealism is what precedes experience; cynicism is what follows.
Of those who say nothing, few are silent.
|
|
#7
|
||||
|
||||
|
Thank you both! Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis |
|
#8
|
||||
|
||||
|
Anyone know if Kaspersky's Script Checker would be able to alert on this HTA Exploit?
__________________
. |
|
#9
|
||||
|
||||
|
Quote:
![]() "2. How the program works ======================== The applications that use "Microsoft Windows Script Host" (Microsoft Explorer, Microsoft Internet Explorer, Microsoft Outlook etc.) send script bodies (VB script, Java script, etc.) to "Script Hosting" to process and execute them. Before these scripts are executed, Kaspersky Anti-Virus Script Checker transfers them to Kaspersky Anti-Virus Monitor to check script bodies for known viruses (in case Kaspersky Anti-Virus Monitor is installed and switched on) and also scans them with heuristic engine if no virus is monitored. In case the suspicious code is found in script body, a user will be informed with warning message and the script execution will be terminated. 3. Virus Definitions ==================== Kaspersky Anti-Virus Script Checker does not use anti-virus database. This database is used by Kaspersky Anti-Virus Scanner and Monitor Kaspersky Anti-Virus Monitor. The main advantage of the ScriptChecker in comparison with other antivirus programs is its ability to warn the user about possible infection with a new virus which is not described in databases yet.
__________________
. |
|
#10
|
||||
|
||||
|
Not at all, I think it is a good question. While it would not be expected to detect the WinMain exe it might be the case it would detect the
c:\winlog.html file that has been associated with it. You might want to see Tony Klein's remarks in this thread http://www.wilderssecurity.com/showt...11878;start=15 Regards, Dan
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland) |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|