MS05-002!exploit on Windows XP Pro SP2

MS05-002!exploit on Windows XP Pro SP2

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
MS05-002!exploit on Windows XP Pro SP2 eli 06-11-2006
Posted by eli on June 11, 2006, 11:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello:

Twice in the past two days, I have been notified by my Zone Allarm Security
Suite Version 6.1 that the: "MS05-002!exploit" was detected in the IE TIF
and repaired. .

Prior to the appearance of this On-Access Zone Alarm alert, the Sun Java
Console in IE 6
popped open for no particular reason. [I have JRE 1.5.0.05 installed].

When I clicked on the link given by Zone Alarm, I was led to this Microsoft
site:


http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx

At that site, I'm told that:

"Non-Affected Software:

Microsoft Windows XP Service Pack 2"

Yet I have windows XP SP2 as my OS.


Why am I getting these repeated virus/exploits on this supposedly
non-affected system?

How might I prevent them in the future?

Thanks in advance:

-Eli

*************************************

Windows XP Professional Edition SP2 with critical Windows Updates
installed

AntiVirus: Zone Alarm Security Suite : 6.1.744.001
Operating System: Windows XP Professional Edition SP2 with critical updates
installed






Posted by Shenan Stanley on June 11, 2006, 11:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
eli wrote:
> Twice in the past two days, I have been notified by my Zone Allarm
> Security Suite Version 6.1 that the: "MS05-002!exploit" was
> detected in the IE TIF and repaired. .
>
> Prior to the appearance of this On-Access Zone Alarm alert, the Sun
> Java Console in IE 6
> popped open for no particular reason. [I have JRE 1.5.0.05
> installed].
> When I clicked on the link given by Zone Alarm, I was led to this
> Microsoft site:
>
>
> http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
>
> At that site, I'm told that:
>
> "Non-Affected Software:
>
> Microsoft Windows XP Service Pack 2"
>
> Yet I have windows XP SP2 as my OS.
>
>
> Why am I getting these repeated virus/exploits on this supposedly
> non-affected system?
>
> How might I prevent them in the future?
>
> Thanks in advance:
>
> -Eli
>
> *************************************
>
> Windows XP Professional Edition SP2 with critical Windows
> Updates installed
>
> AntiVirus: Zone Alarm Security Suite : 6.1.744.001
> Operating System: Windows XP Professional Edition SP2 with critical
> updates installed

I will quote David Lipman.. And then let someone else dive deeper into your
troubles..

-----
If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to
JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
This is most likely why you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of
Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0
Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp
-----

In other words - I suggest that you update your Java stuff to the latest
release ASAP..

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by eli on June 12, 2006, 12:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Shenan wrote:

"If you are using any version of Sun Java that is prior to JRE Version 5.0,
> then you are strongly urged to remove any/all versions that are prior to
> JRE/JSE
> Version 5.0."

Thanks for your response, Shenan, but the JRE Version I'm using is:

JRE version 1.5.0_05 Java HotSpot(TM) Client VM

It isn't the latest version available; I believe that would be Update 7
rather than Update 5 which is what I now have installed But I dont think its
earlier than the 5.0 youre referring to. I had the Update 6 to JRE 1.5
installed a few months ago, but it kept crashing my IE so I went back to the
5.0 Update, as advised by one of these newsgroups. This was a few months
back...

Not sure if this is the cause of the problem, since its not as early as the
version you are warning me about here.

-Eli

******************************************

> eli wrote:
>> Twice in the past two days, I have been notified by my Zone Allarm
>> Security Suite Version 6.1 that the: "MS05-002!exploit" was
>> detected in the IE TIF and repaired. .
>>
>> Prior to the appearance of this On-Access Zone Alarm alert, the Sun
>> Java Console in IE 6
>> popped open for no particular reason. [I have JRE 1.5.0.05
>> installed].
>> When I clicked on the link given by Zone Alarm, I was led to this
>> Microsoft site:
>>
>>
>> http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
>>
>> At that site, I'm told that:
>>
>> "Non-Affected Software:
>>
>> Microsoft Windows XP Service Pack 2"
>>
>> Yet I have windows XP SP2 as my OS.
>>
>>
>> Why am I getting these repeated virus/exploits on this supposedly
>> non-affected system?
>>
>> How might I prevent them in the future?
>>
>> Thanks in advance:
>>
>> -Eli
>>
>> *************************************
>>
>> Windows XP Professional Edition SP2 with critical Windows
>> Updates installed
>>
>> AntiVirus: Zone Alarm Security Suite : 6.1.744.001
>> Operating System: Windows XP Professional Edition SP2 with critical
>> updates installed
>
> I will quote David Lipman.. And then let someone else dive deeper into
> your troubles..
>
> -----
> If you are using any version of Sun Java that is prior to JRE Version 5.0,
> then you are strongly urged to remove any/all versions that are prior to
> JRE/JSE
> Version 5.0. There are vulnerabilities in them and they are actively
> being exploited.
> This is most likely why you got infected with malware.
>
> Therefore, it is highly suggested that if there are any prior versions of
> Sun Java
> to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version
> 5.0 Update 7
> be installed ASAP.
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version...
>
> C:\Program Files\Java\jre1.5.0_07
>
>
> http://www.java.com/en/download/manual.jsp
> -----
>
> In other words - I suggest that you update your Java stuff to the latest
> release ASAP..
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>



Posted by =?Utf-8?B?UGFuZGFfbWFu?= on June 12, 2006, 1:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
My reply is at the bottom of your message :


"eli" wrote:

>Hello:
>
>Twice in the past two days, I have been notified by my Zone Allarm Security
>Suite Version 6.1 that the: "MS05-002!exploit" was detected in the IE TIF
>and repaired. .
>
>Prior to the appearance of this On-Access Zone Alarm alert, the Sun Java
>Console in IE 6
>popped open for no particular reason. [I have JRE 1.5.0.05 installed].
>
>When I clicked on the link given by Zone Alarm, I was led to this Microsoft
>site:
>
>
> http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
>
>At that site, I'm told that:
>
>"Non-Affected Software:
>
>Microsoft Windows XP Service Pack 2"
>
>Yet I have windows XP SP2 as my OS.
>
>
>Why am I getting these repeated virus/exploits on this supposedly
>non-affected system?
>
>How might I prevent them in the future?
>
>Thanks in advance:
>
>-Eli
>



Hello.It must be false-positive , in other words ,a mistake .
This often happens to products with such ^protection^ . By the way I had
similar issue with my ex-antivirus telling me I am vulnerable and I did had
all updated from Windows Update + SP2 .
If Windows Updates shows you have all updates downloaded and if you have SP2
, then no problems . You may wish to contact ZoneLabs (the makers of
ZoneAlarm) so that they fix that .
http://www.zonelabs.com


Panda_man
--
Bronze level Contributor
http://pandaman.my.contact.bg
Please , rate posts

Posted by eli on June 12, 2006, 2:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks Panda Man:

Was thinking it might be a false-positive, but since the Zone Alarm
specified a file in the IE TIF which it needed to fix, was wondering if it
was some real infection/exploit...It wasnt the Firewall but the AntiVirus
component of theZone Alarm which sent out the alert and did the "fixing".

I did notify Zone Alarm of this via email.

Do you should think it would be necessary and/or helpful to upgrade that.
Java JRE program as Shenan had recommended earlier? Or does that not apply
to JRE 1.5 Upgrade 5.0 which I now have installed?

Thanks again:

Eli

**************************************
> My reply is at the bottom of your message :
>
>
> "eli" wrote:
>
>>Hello:
>>
>>Twice in the past two days, I have been notified by my Zone Allarm
>>Security
>>Suite Version 6.1 that the: "MS05-002!exploit" was detected in the IE TIF
>>and repaired. .
>>
>>Prior to the appearance of this On-Access Zone Alarm alert, the Sun Java
>>Console in IE 6
>>popped open for no particular reason. [I have JRE 1.5.0.05 installed].
>>
>>When I clicked on the link given by Zone Alarm, I was led to this
>>Microsoft
>>site:
>>
>>
>> http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
>>
>>At that site, I'm told that:
>>
>>"Non-Affected Software:
>>
>>Microsoft Windows XP Service Pack 2"
>>
>>Yet I have windows XP SP2 as my OS.
>>
>>
>>Why am I getting these repeated virus/exploits on this supposedly
>>non-affected system?
>>
>>How might I prevent them in the future?
>>
>>Thanks in advance:
>>
>>-Eli
>>
>
>
>
> Hello.It must be false-positive , in other words ,a mistake .
> This often happens to products with such ^protection^ . By the way I had
> similar issue with my ex-antivirus telling me I am vulnerable and I did
> had
> all updated from Windows Update + SP2 .
> If Windows Updates shows you have all updates downloaded and if you have
> SP2
> , then no problems . You may wish to contact ZoneLabs (the makers of
> ZoneAlarm) so that they fix that .
> http://www.zonelabs.com
>
>
> Panda_man
> --
> Bronze level Contributor
> http://pandaman.my.contact.bg
> Please , rate posts



Similar ThreadsPosted
Re: Windows Trojan January 20, 2006, 6:01 pm
Windows.ActiveDesktop February 7, 2006, 5:16 pm
Windows Defender September 6, 2006, 6:24 am
Windows Trojan January 12, 2006, 4:47 am
Windows Defender January 3, 2007, 2:59 am
Windows Defender March 25, 2007, 11:03 am
MSN windows going crazy April 18, 2007, 11:56 am
Re: my windows xp frozen May 19, 2007, 8:56 am
RE: my windows xp frozen May 21, 2007, 9:07 am
Windows.exe error August 5, 2007, 10:12 am

The site map in XML format XML site map

Contact Us | Privacy Policy