I’ve come up with two common-sense ideas for avoiding DLL Hijack attacks. Nothing high-tech or fancy. No Registry changes that may break other apps. J
[See the full post at: Avoiding DLL Hijacks]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Avoiding DLL Hijacks
Home » Forums » Newsletter and Homepage topics » Avoiding DLL Hijacks
- This topic has 6 replies, 3 voices, and was last updated 14 years, 8 months ago.
Tags: DLL hijacking
AuthorTopicViewing 5 reply threadsAuthorReplies-
Randall
GuestAugust 29, 2010 at 1:41 am #57859Woody,
Great tips that everyone can easily do! Thanks for posting this.
Your article also mentions that corporates have their firewall set to avoid most WebDAV and SMB problems. I’m not clear whether home users are likely to run into WebDAV and SMB.
Should we be using the non-registry changes suggested by Microsoft (to disable the WebClient service and block ports 139 and 445?
Or is this WebDav and SMB stuff unlikely to apply to a home user?
Thanks again for your good advice
Randall -
woody
Manager -
rc primak
GuestAugust 29, 2010 at 12:40 pm #57861I sometimes download Zipped Folders for running non-installed applications on my computers. Does the mere act of Extracting All from a Zipped Folder risk running a rogue DLL? Or can I Extract All, then identify the pest and zap it before it can do any harm?
Of course, if I EVER find an infected file in a Zipped archive being offered as a non-installed Application, I would be inclined to stop doing business with the offending web site or author.
-
woody
ManagerAugust 30, 2010 at 5:45 pm #57862@RC –
Unzipping won’t do it, except in a weird way. I see that IZARC is listed as a program susceptible to DLL Hijacking, with the automatically called program ztv7z.dll. (See http://www.corelan.be:8800/index.php/2010/08/25/dll-hijacking-kb-2269637-the-unofficial-list/ )
This gets complicated, but if you have IZARC set up as your default ZIP handler, and you have a ZIP file sitting in the same folder as a jiggered ztv7z.dll file, when you double-click on the ZIP file, your machine runs the bogus ztv7z.dll program.
So in that (rare) instance, yes, unzipping a file can run a bad program.
-
rc primak
GuestAugust 30, 2010 at 11:31 pm #57863I find on the list (which is hardly complete) most troubling the listing for NVidia Drivers. That could lead to a hardware or firmware infection. Very troubling.
Also, Avast is probably not the only security product which has a vulnerability, but I don’t like seeing it there either.
Notably, VLC Player has recently been patched to eliminate this vulnerability. Good on VideoLAN for that one!
-
EP
AskWoody_MVPSeptember 25, 2010 at 6:53 am #57864Microsoft has released the KB2264107 patches that may deal with the DLL Hijacking problem:
http://support.microsoft.com/kb/2264107the 2264107 updates will be published at the Windows Update site on Tuesday Sept. 28.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
KB5058379 / KB 5061768 Failures
by
crown
26 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
34 minutes ago -
At last – installation of 24H2
by
Botswana12
1 hour, 19 minutes ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
10 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
13 hours, 31 minutes ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
6 hours, 50 minutes ago -
Limited account permission error related to Windows Update
by
gtd12345
1 day, 2 hours ago -
Another test post
by
gtd12345
1 day, 3 hours ago -
Connect to someone else computer
by
wadeer
21 hours, 30 minutes ago -
Limit on User names?
by
CWBillow
1 day ago -
Choose the right apps for traveling
by
Peter Deegan
14 hours, 30 minutes ago -
BitLocker rears its head
by
Susan Bradley
23 hours, 5 minutes ago -
Who are you? (2025 edition)
by
Will Fastie
20 minutes ago -
AskWoody at the computer museum, round two
by
Will Fastie
16 hours, 53 minutes ago -
A smarter, simpler Firefox address bar
by
Alex5723
1 day, 13 hours ago -
Woody
by
Scott
1 day, 22 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
22 hours, 10 minutes ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
2 days, 13 hours ago -
MS Office 365 Home on MAC
by
MickIver
2 days, 6 hours ago -
Google’s Veo3 video generator. Before you ask: yes, everything is AI here
by
Alex5723
3 days, 3 hours ago -
Flash Drive Eject Error for Still In Use
by
J9438
1 hour, 55 minutes ago -
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
3 days, 21 hours ago -
Windows 11 Insider Preview build 26120.4161 (24H2) released to BETA
by
joep517
3 days, 21 hours ago -
AI model turns to blackmail when engineers try to take it offline
by
Cybertooth
3 days, 1 hour ago -
Migrate off MS365 to Apple Products
by
dmt_3904
3 days, 2 hours ago -
Login screen icon
by
CWBillow
2 days, 16 hours ago -
AI coming to everything
by
Susan Bradley
7 hours, 21 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
4 days, 13 hours ago -
No Screen TurnOff???
by
CWBillow
4 days, 13 hours ago -
Identify a dynamic range to then be used in another formula
by
BigDaddy07
4 days, 14 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.