Windows XP 用の更新プログラム (KB916595) 簡単な説明 この更新プログラムは、Windows XP コンピュータに対する信頼性に関するものです。 この更新プログラムをインストールすると、Windows XP Service Pack 2 を実行しているコンピュータで "Stop 0xD" というエラーメッセージが表示されるという問題が発生しなくなります。
This issue is NOT a vulnerability, this is a Windows feature, and the BITS service behaviour is expected to be like this. This is also NOT a firewall vulnerability. By default you may have fully allowed svchost.exe (access to ports 80 and 443) to access the Internet (if you enabled automatic Windows update), but knowing this issue, you may now consider to reconfigure it.
The only way to prevent abuses is to restrict in your firewall the IPs svchost.exe (or services.exe) is allowed to access. On my side, I need to allow these IP ranges
Finally, disabling all together the automatic update service and BITS service is not a solution. Indeed, a malware could start them back before using them. I do not advise at all to disable Automatic Windows Updates, but if you go that way, do not forget to also block svchost.exe or services.exe in your firewall (if you are using DHCP, create a rule to allow local port 68 to communicate in UDP to the remote port 67, IP 255.255.255.255).
Filename Result kage.exe FALSE POSITIVE The file 'kage.exe' has been determined to be 'FALSE POSITIVE'. Detection will be removed from our virus definition file (VDF) with one of the next updates.
24.05.2007,08:34:16 - Connection failed while downloading the file http://dl5.avgate.net/upd/idx/master.idx. 24.05.2007,08:34:16 - Switching to next update server 24.05.2007,08:34:19 - Connection failed while downloading the file http://dl1.avgate.net/upd/idx/master.idx. 24.05.2007,08:34:19 - Switching to next update server 24.05.2007,08:34:21 - Connection failed while downloading the file http://dl2.avgate.net/upd/idx/master.idx. 24.05.2007,08:34:21 - Switching to next update server 24.05.2007,08:34:24 - Connection failed while downloading the file http://dl6.avgate.net/upd/idx/master.idx. 24.05.2007,08:34:24 - Switching to next update server 24.05.2007,08:34:33 - Registry entry created successfully: Software\H+BEDV\AntiVir PersonalEdition Classic V 7 |UpdateInProgress
AV-Test.org, an independent testing group at the Otto-von-Guericke-University (Magdeburg, Germany), tested 29 anti-malware products with a very large set of files (606,901 to be specific). The goal was to test detection capabilities only, not cleaning. Products were set with their most aggressive detection options, such as using all heuristics and testing inside archives.
AV-Test.org について AV-Test.org は、Magdeburg 大学と GEGA IT-Solutions GbR の共同リサーチプロジェクトです。 ドイツにある Otto-von-Guericke 大学 Magdeburg 校は、学生数1万3500人を超え、 Institute of Technical and Business Information systems の Workgroup Business Information Systems にある研究ラボにて これらのテストは実施されています。現在、このウイルステストラボでは、 常時、教授2名、学生約15名が、ウイルス複製、解析、ウイルス対策製品のテストに携わっています。 GEGA IT-Solutions GbR は、セキュリティコンサルティング会社で、 特にコンピュータウイルス感染に焦点を絞った活動を行っています。