Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

2 exploits identified--how to remove?

 
   Security Forums (Home) -> General Discussions RSS
Next:  BugHunter Updated v2.2e January 23rd, 2008  
Author Message
MB_

External


Since: Jan 04, 2005
Posts: 36



(Msg. 1) Posted: Sat Jan 26, 2008 2:35 pm
Post subject: 2 exploits identified--how to remove?
Archived from groups: alt>comp>anti-virus (more info?)

I ran AVG and it found:

324123[1].html Exploit.anl

sploit[1].anr Exploit.MS05-002


AVG is still running so maybe it will remove it afterwards.

But, if not, how do I remove it?

Mel

 >> Stay informed about: 2 exploits identified--how to remove? 
Back to top
Login to vote
MZB

External


Since: Oct 29, 2005
Posts: 38



(Msg. 2) Posted: Sat Jan 26, 2008 3:16 pm
Post subject: Re: 2 exploits identified--how to remove? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Well, I guess I jumped the gun.
It says it deleted it.

Hope that's true and it doesn't return!

Mel


"MB_" <mel.TakeThisOut@prodigy.invalid.net> wrote in message
news:rYLmj.44$jw7.26@newsfe02.lga...
>I ran AVG and it found:
>
> 324123[1].html Exploit.anl
>
> sploit[1].anr Exploit.MS05-002
>
>
> AVG is still running so maybe it will remove it afterwards.
>
> But, if not, how do I remove it?
>
> Mel
>
>
>

 >> Stay informed about: 2 exploits identified--how to remove? 
Back to top
Login to vote
VanguardLH

External


Since: Sep 14, 2007
Posts: 18



(Msg. 3) Posted: Sat Jan 26, 2008 3:50 pm
Post subject: Re: 2 exploits identified--how to remove? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"MB_" wrote in message news:rYLmj.44$jw7.26@newsfe02.lga...
>I ran AVG and it found:
>
> 324123[1].html Exploit.anl

You sure that wasn't "Exploit.ani"?
http://www.cio.com/article/103055/More_Than_K_Sites_Now_Exploit_.ANI_S...rity_Vu
http://www.pctools.com/mrc/infections/id/Exploit.ANI/

> sploit[1].anr Exploit.MS05-002
http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
A really old exploit (same one as above).

> AVG is still running so maybe it will remove it afterwards.
> But, if not, how do I remove it?

Since your other post says that AVG deleted the files that
incorporated those browser exploits, probably from your TIF cache,
don't revisit those sites, or add them in the Restricted Sites
security zone (or in your hosts file so you can't get there anymore
unless you have URL blocking in your firewall or an IE plug-in, like
IE7Pro). Depends on WHERE the pest was detected. Maybe it is in a
System Restore point (which means AVG can't delete it) or in your
Recycle Bin.
 >> Stay informed about: 2 exploits identified--how to remove? 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1719



(Msg. 4) Posted: Sat Jan 26, 2008 11:32 pm
Post subject: Re: 2 exploits identified--how to remove? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "MZB" <moo DeleteThis @noway.prudigy.net>

| Well, I guess I jumped the gun.
| It says it deleted it.
|
| Hope that's true and it doesn't return!
|
| Mel
|

They are exploit codes found in the browser cache and when you went to a malicious site they
were blocked or, hopefully, it wasn't a case where you went to a web site a while back and
during a scan these exploit codes were subsequently found in the browser cache.

They won't "return" unless you revisit that specific site that hosted the malicious codes or
other malicious sites.

Example log even from McAfee when visiting a malicious site...
1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman D:\temp\IE6\Temporary
Internet Files\Content.IE5\C5I301U7\324123[1].htm Exploit-ANIfile.c

The reason why the above indicates "Delete failed (Clean failed)" is because the file wasn't
allowed to be written to the cache and was blocked.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: 2 exploits identified--how to remove? 
Back to top
Login to vote
MZB

External


Since: Oct 29, 2005
Posts: 38



(Msg. 5) Posted: Sat Jan 26, 2008 11:54 pm
Post subject: Re: 2 exploits identified--how to remove? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

>>>>>>>>>>>>>>>>
hopefully, it wasn't a case where you went to a web site a while back and
during a scan these exploit codes were subsequently found in the browser
cache.

>>>>>>>>>>>>>>>>>>>>>>.

David:

Unfortunately, I must assume that's the case.

I only discovered the problem by routinely running AVG. I don't recall
anything popping up while I was at a site indicating any problem.

Hopefully, no damage was done.

Mel



"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:6qPmj.5824$O9.5667@trnddc01...
> From: "MZB" <moo.RemoveThis@noway.prudigy.net>
>
> | Well, I guess I jumped the gun.
> | It says it deleted it.
> |
> | Hope that's true and it doesn't return!
> |
> | Mel
> |
>
> They are exploit codes found in the browser cache and when you went to a
> malicious site they
> were blocked or, hopefully, it wasn't a case where you went to a web site
> a while back and
> during a scan these exploit codes were subsequently found in the browser
> cache.
>
> They won't "return" unless you revisit that specific site that hosted the
> malicious codes or
> other malicious sites.
>
> Example log even from McAfee when visiting a malicious site...
> 1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman
> D:\temp\IE6\Temporary
> Internet Files\Content.IE5\C5I301U7\324123[1].htm Exploit-ANIfile.c
>
> The reason why the above indicates "Delete failed (Clean failed)" is
> because the file wasn't
> allowed to be written to the cache and was blocked.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
 >> Stay informed about: 2 exploits identified--how to remove? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Undeletable Exploits - Kapersky reports these files but won't delete them: Local Settings\Temp\Temporary Internet Files\Content.IE5\SDIFK1QZ\1[1].htm suspicion: Exploit.HTML.Mht Local Settings\Temp\Temporary Internet Files\Content.IE5\SDIFK1QZ\rg[1].htm suspicion:..

Microsoft hunting down exploits - ftp://ftp.research.microsoft.com/pub/tr/TR-2005-72.pdf A good read. --- Lord, protect me from those to whom you speak directly All salute the new age, and I hope nobody escapes

Remove me please! - Someone from DLipman@Verizon.Net keeps sending me spam regarding this mailing list. Please remove me from this list!

How remove 3721 - I already installed PestPatrol Control, but it just cannot remove 3721 even it reported deleted. Can anyone help ?

add and remove?? - Hi I went to open add and remove and it doesn't open. I've ran Spybot SD...Adaware...AVG6 (complete scan) plus HijackThis. They're all updated also with latest definitions etc.etc And they all come up clean. So I'm wondering if it's been corrupted or..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]