Tech Support > Computers & Technology > Computer Security > had installed Ilfak Guilfanov's patch v. MS patch
had installed Ilfak Guilfanov's patch v. MS patch
Posted by none on January 8th, 2006


I installed this Guilfanov
patch for the WMF vulnerability a
couple of weeks ago. I'd read on GRC's pages that
this install would show up in the add/remove section,
and could be removed from there,
but didn't check to see. After MS put out the patch
I considered unistalling Guilfanov's and looked. It
wasn't listed. I installed MS patch over the top,
and noted no problem.

Oddly enough, when I went back to review GRC's pages
I could not find any information about uninstalling
Guilfanov's patch!

With all the paranoia there about CIA, NSA, etc..,
I'm beginning to wonder if I haven't installed the
real trojan, which is Guilfanov's!

Any help on all this?

Posted by Donnie on January 9th, 2006



"none" <none@nobody.no> wrote in message
news:43c196f5$0$1531$c3e8da3@news.astraweb.com...
http://www.hexblog.com/
According to Guilfanov, that's the way to uninstall it. Run
netstat -an to look for any unwanted connections if you think that you
installed a trojan instead.
It could be that it never really installed in the first place. See if it's
in the startup on msconfig and look in the registry
HKLM
Software
Microsoft
Windows
Run
################################################



Posted by Donnie on January 9th, 2006


Reading a little further, I see that MS says that w2k sp4 is vunerable. Does
that mean that w2k running any sp other than 4 is NOT vunerable?
donnie
##################################


Posted by none on January 9th, 2006


Donnie wrote:
Apparently, from this page:
http://castlecops.com/a6445-WMF_Exploit_FAQ.html
The uninstall for this hotfix is inside the following folder;
#21
# Can I un-install the hotfix across a network?

Yes, the un-installer is found here:

c:\Program Files\WindowMetafile\Fixunins000.exe

Have yet to reboot and return to Windows update to see if I
still have their fix, and/or how to remove it and then reinstall it.


Posted by Ant on January 9th, 2006


"Donnie" wrote:

I can confirm that W2k SP2 *is* vulnerable.




Similar Posts