2 exploits identified--how to remove?

2 exploits identified--how to remove?

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
2 exploits identified--how to remove? MB_ 01-26-2008
Posted by MB_ on January 26, 2008, 2:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I ran AVG and it found:

324123[1].html Exploit.anl

sploit[1].anr Exploit.MS05-002


AVG is still running so maybe it will remove it afterwards.

But, if not, how do I remove it?

Mel




Posted by MZB on January 26, 2008, 3:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Well, I guess I jumped the gun.
It says it deleted it.

Hope that's true and it doesn't return!

Mel


>I ran AVG and it found:
>
> 324123[1].html Exploit.anl
>
> sploit[1].anr Exploit.MS05-002
>
>
> AVG is still running so maybe it will remove it afterwards.
>
> But, if not, how do I remove it?
>
> Mel
>
>
>



Posted by David H. Lipman on January 26, 2008, 6:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Well, I guess I jumped the gun.
| It says it deleted it.
|
| Hope that's true and it doesn't return!
|
| Mel
|

They are exploit codes found in the browser cache and when you went to a
malicious site they
were blocked or, hopefully, it wasn't a case where you went to a web site a
while back and
during a scan these exploit codes were subsequently found in the browser cache.

They won't "return" unless you revisit that specific site that hosted the
malicious codes or
other malicious sites.

Example log even from McAfee when visiting a malicious site...
1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman
D:\temp\IE6\Temporary
Internet Files\Content.IE5\C5I301U74123[1].htm Exploit-ANIfile.c

The reason why the above indicates "Delete failed (Clean failed)" is because the
file wasn't
allowed to be written to the cache and was blocked.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by MZB on January 26, 2008, 11:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>>>>>>>>>>>>>>>>
hopefully, it wasn't a case where you went to a web site a while back and
during a scan these exploit codes were subsequently found in the browser
cache.

>>>>>>>>>>>>>>>>>>>>>>.

David:

Unfortunately, I must assume that's the case.

I only discovered the problem by routinely running AVG. I don't recall
anything popping up while I was at a site indicating any problem.

Hopefully, no damage was done.

Mel



>
> | Well, I guess I jumped the gun.
> | It says it deleted it.
> |
> | Hope that's true and it doesn't return!
> |
> | Mel
> |
>
> They are exploit codes found in the browser cache and when you went to a
> malicious site they
> were blocked or, hopefully, it wasn't a case where you went to a web site
> a while back and
> during a scan these exploit codes were subsequently found in the browser
> cache.
>
> They won't "return" unless you revisit that specific site that hosted the
> malicious codes or
> other malicious sites.
>
> Example log even from McAfee when visiting a malicious site...
> 1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman
> D:\temp\IE6\Temporary
> Internet Files\Content.IE5\C5I301U74123[1].htm Exploit-ANIfile.c
>
> The reason why the above indicates "Delete failed (Clean failed)" is
> because the file wasn't
> allowed to be written to the cache and was blocked.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by VanguardLH on January 26, 2008, 4:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I ran AVG and it found:
>
> 324123[1].html Exploit.anl

You sure that wasn't "Exploit.ani"?
http://www.cio.com/article/103055/More_Than_K_Sites_Now_Exploit_.ANI_Security_Vulnerability
http://www.pctools.com/mrc/infections/id/Exploit.ANI/

> sploit[1].anr Exploit.MS05-002
http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
A really old exploit (same one as above).

> AVG is still running so maybe it will remove it afterwards.
> But, if not, how do I remove it?

Since your other post says that AVG deleted the files that
incorporated those browser exploits, probably from your TIF cache,
don't revisit those sites, or add them in the Restricted Sites
security zone (or in your hosts file so you can't get there anymore
unless you have URL blocking in your firewall or an IE plug-in, like
IE7Pro). Depends on WHERE the pest was detected. Maybe it is in a
System Restore point (which means AVG can't delete it) or in your
Recycle Bin.


Similar ThreadsPosted
Microsoft hunting down exploits August 7, 2005, 2:35 am
Virus exploits London Tube bombs July 11, 2005, 11:13 pm
Can't remove r.exe!!! June 24, 2005, 3:37 pm
how do I remove this? October 13, 2005, 2:37 pm
Tried KIS 6 and had to remove it September 25, 2006, 2:59 pm
logjda.dll - how to remove? June 4, 2005, 6:27 am
WinFixer2005 - how to remove? September 26, 2005, 1:32 pm
How To Remove q5760749_disk.dll October 18, 2005, 10:39 am
how to remove ppdoor.fh December 7, 2005, 6:14 pm
cannot remove WebP2PInstaller.dll December 17, 2005, 12:19 am

The site map in XML format XML site map

Contact Us | Privacy Policy