ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Windows Trojan confusion abounds

Joris Evers CNET News.com

Published: 11 Nov 2005 10:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Trend Micro on Wednesday reported the discovery of a Trojan horse that it said attacked Windows users through an image rendering flaw in Windows, a day after Microsoft provided a fix for the bug — but now it isn't so sure.

The Trojan is referred to as "emfsploit.a" by the antivirus company. Initially Trend Micro reported that the malicious code would crash "explorer.exe" on unpatched Windows machines. Explorer runs key parts of the Windows graphical user interface, including the Start menu, taskbar, desktop and file manager.

But late on Thursday Trend Micro said its initial analysis of the Trojan might be incorrect.

"We asked another team to start the disassembly process again," said Raimund Genes, chief technologist for Trend Micro in Europe. That means researchers will reinvestigate the Trojan code to see what it does.

Meanwhile, Trend Micro updated the entry in its antivirus encyclopaedia on the Trojan. The entry no longer states that "emfsploit.a" exploits the Windows vulnerability, but instead it says that it "exhibits behaviour similar to the Enhanced Metafile vulnerability of MS05-053."

"Our Trend Labs team is currently working with Microsoft to resolve whether TROJ_EMFSPLOIT.A does indeed fall under the category of code exploiting the MS05-053 vulnerability or whether it is only a related piece of code but not totally exploiting MS05-053," Genes said in an e-mail to ZDNet UK's sister site, CNET News.com.

Trend Micro has found that the Trojan does cause a crash on certain Windows XP systems, but the finding is not consistent with Microsoft's Tuesday bug report. Trend found a crash only on Windows XP computers without Service Pack 1. But according to Microsoft, the vulnerability also affects systems with SP1 and SP2, so these should crash as well if the Trojan indeed exploits the MS05-053 flaw.

Trend Micro describes the new Trojan as a "proof of concept". It received one sample of the code from a customer in Japan, but as of late Thursday the Trojan hasn't actually been detected anywhere else, Genes said. The company hence rates the overall risk "low".

The vulnerability the Trojan was thought to exploit lies in the way Windows handles certain graphics files. Microsoft provided a fix for three such flaws on Tuesday as part of its monthly patching cycle.

The Windows vulnerabilities relate to how the operating system renders the Windows Metafile (WMF) and Enhanced Metafile (EMF) image formats, Microsoft said on Tuesday in its MS05-053 security bulletin. The software maker tagged the bulletin "critical", its most serious rating.

A Microsoft representative said the company is investigating the Trojan report, but added that it is not currently aware of attacks that use it.

Microsoft urges Windows users to apply the MS05-053 update as soon as possible. However, some users of Microsoft's free Software Update Services patching tool have reported trouble in obtaining the patch.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
54 out of 92 people found this useful



Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Senior Tester - Essex - 40k - Financial Markets (FIX)

My client based in Essex is a leading player in the FIX Market and are exclusively a Microsoft Development House using the latest tools such as ...

Linux Redhat Systems Administrator - Windows XP, Network Connectivity

Linux Redhat Systems Administrator - Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). Fantastic opportunity ...

FIX Application Support

My client is a leading software house, who is seeking an ambitious FIX Application Support Analyst. Some of the activities will involve reproduction ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.