Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

View previous topic View next topic Go down  Message [Page 1 of 1]

DragonMaster Jay


Site Owner
Site Owner
Duqu was a zero-day exploit and awaited a bugfix by Microsoft. This malware installed itself by using a Word document with the malcode embedded, that once executed, distributes the Duqu code on to the machine.

Some researchers speculate relation to Stuxnet, but all the details cannot be verified. Its main relation is using stolen certificates to sign drivers, inserted with arbitrary code.

Symantec states this installer is downloaded from status updates. The main research lab investigating, whom first discovered, would be CrySyS Lab.

Microsoft has released an official workaround.

The automatic fix (but occasionally buggy depending on system configuration) is using a FixIt Tool with title: "Microsoft Security Advisory: Vulnerability in TrueType font parsing could allow elevation of privileges". This can also be obtained in the recent critical update released in Microsoft Update.

To apply the workaround manually, users of 32-bit systems can enter the following at an elevated command prompt:

Echo y| cacls "%windir%\system32\t2embed.dll" /E /P everyone:N

For 64-bit systems, users should enter both of these at an elevated command prompt:

Echo y| cacls "%windir%\system32\t2embed.dll" /E /P everyone:N

Echo y| cacls "%windir%\syswow64\t2embed.dll" /E /P everyone:N


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum