The latest vulnerability attack caused "XP Help" to somehow pop up

  

Recently, the Windows XP system has been released with the latest 0ady vulnerability (CVE-2010-1885). Hackers can use this to invade websites and embed vulnerability code in the ASX file of the website server. When users browse these websites, their personal computers will Will be invaded by Trojans and then automatically download a variety of hacking Trojans, malignant viruses and so on. During the process of hanging the horse, the Help and Support Center of the user system will pop up actively.

As of press time, Microsoft has not released a patch for this vulnerability. Rising security experts said that the "anti-hanging horse" function in Rising Anti-Virus 2010 uses behavioral feature technology to actively intercept this attack. (Rising anti-virus software half-year free version download address http://www.newhua.com/soft/15949.htm)

According to reports, the vulnerability was previously disclosed by Google engineer Tavis Ormandy, its exploit code is online Publicly, experts predict that attacks that exploit this vulnerability will soon be on a large scale. According to the monitoring of “Rising Cloud Security System”, there is no domestic website that exploits this vulnerability. However, hackers have discussed it on bad websites. I believe that there will be actual attack cases soon.

Rising security experts said the vulnerability is mainly for Windows XP and 2003 systems. When a user visits a website with malicious code, the system's Help and Support Center page will pop up. This is also a clear feature of judging the computer being attacked by this vulnerability. When the user sees the pop-up, the Trojan has invaded the user's computer and has secretly downloaded a large number of other viruses.


(Help and Support Center page popped up by attacked computer)

Rising security experts remind users that Windows XP system is still widely used by computer users in China. The market share is as high as 63%, and some of the users use non-genuine operating systems, and the patches cannot be updated normally. In this case, once a new vulnerability is exploited by a hacker for a large-scale hacking attack, the user's computer will be in a very dangerous situation. After the user visits the website or listens to malicious audio files, the computer will continue to download Trojans and steal personal account passwords and privacy data. In serious cases, the computer may freeze and not work properly.

Since Microsoft has not provided a patch for this vulnerability, Rising experts recommend that users can use the following methods to prevent attacks:

1. For users who do not have professional anti-virus software installed, you can refer to Microsoft. Temporary workaround to temporarily disable the HCP protocol.

Specific method:

Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\\HCP]

Save the above as "Repair CVE-2010-1885. Reg file, double click to run the import registry. Please back up the contents of the registry if necessary.




Copyright © Windows knowledge All Rights Reserved