PC Review


Reply
Thread Tools Rate Thread

2 exploits identified--how to remove?

 
 
MB_
Guest
Posts: n/a
 
      26th Jan 2008
I ran AVG and it found:

324123[1].html Exploit.anl

sploit[1].anr Exploit.MS05-002


AVG is still running so maybe it will remove it afterwards.

But, if not, how do I remove it?

Mel



 
Reply With Quote
 
 
 
 
MZB
Guest
Posts: n/a
 
      26th Jan 2008
Well, I guess I jumped the gun.
It says it deleted it.

Hope that's true and it doesn't return!

Mel


"MB_" <(E-Mail Removed)> wrote in message
news:rYLmj.44$(E-Mail Removed)...
>I ran AVG and it found:
>
> 324123[1].html Exploit.anl
>
> sploit[1].anr Exploit.MS05-002
>
>
> AVG is still running so maybe it will remove it afterwards.
>
> But, if not, how do I remove it?
>
> Mel
>
>
>



 
Reply With Quote
 
VanguardLH
Guest
Posts: n/a
 
      26th Jan 2008
"MB_" wrote in message news:rYLmj.44$(E-Mail Removed)...
>I ran AVG and it found:
>
> 324123[1].html Exploit.anl


You sure that wasn't "Exploit.ani"?
http://www.cio.com/article/103055/Mo..._Vulnerability
http://www.pctools.com/mrc/infections/id/Exploit.ANI/

> sploit[1].anr Exploit.MS05-002

http://www.microsoft.com/technet/sec.../ms05-002.mspx
A really old exploit (same one as above).

> AVG is still running so maybe it will remove it afterwards.
> But, if not, how do I remove it?


Since your other post says that AVG deleted the files that
incorporated those browser exploits, probably from your TIF cache,
don't revisit those sites, or add them in the Restricted Sites
security zone (or in your hosts file so you can't get there anymore
unless you have URL blocking in your firewall or an IE plug-in, like
IE7Pro). Depends on WHERE the pest was detected. Maybe it is in a
System Restore point (which means AVG can't delete it) or in your
Recycle Bin.

 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      26th Jan 2008
From: "MZB" <(E-Mail Removed)>

| Well, I guess I jumped the gun.
| It says it deleted it.
|
| Hope that's true and it doesn't return!
|
| Mel
|

They are exploit codes found in the browser cache and when you went to a malicious site they
were blocked or, hopefully, it wasn't a case where you went to a web site a while back and
during a scan these exploit codes were subsequently found in the browser cache.

They won't "return" unless you revisit that specific site that hosted the malicious codes or
other malicious sites.

Example log even from McAfee when visiting a malicious site...
1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman D:\temp\IE6\Temporary
Internet Files\Content.IE5\C5I301U7\324123[1].htm Exploit-ANIfile.c

The reason why the above indicates "Delete failed (Clean failed)" is because the file wasn't
allowed to be written to the cache and was blocked.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
MZB
Guest
Posts: n/a
 
      27th Jan 2008
>>>>>>>>>>>>>>>>
hopefully, it wasn't a case where you went to a web site a while back and
during a scan these exploit codes were subsequently found in the browser
cache.

>>>>>>>>>>>>>>>>>>>>>>.


David:

Unfortunately, I must assume that's the case.

I only discovered the problem by routinely running AVG. I don't recall
anything popping up while I was at a site indicating any problem.

Hopefully, no damage was done.

Mel



"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:6qPmj.5824$O9.5667@trnddc01...
> From: "MZB" <(E-Mail Removed)>
>
> | Well, I guess I jumped the gun.
> | It says it deleted it.
> |
> | Hope that's true and it doesn't return!
> |
> | Mel
> |
>
> They are exploit codes found in the browser cache and when you went to a
> malicious site they
> were blocked or, hopefully, it wasn't a case where you went to a web site
> a while back and
> during a scan these exploit codes were subsequently found in the browser
> cache.
>
> They won't "return" unless you revisit that specific site that hosted the
> malicious codes or
> other malicious sites.
>
> Example log even from McAfee when visiting a malicious site...
> 1/23/2008 8:55:55 PM Delete failed (Clean failed) DLIPMAN-1\lipman
> D:\temp\IE6\Temporary
> Internet Files\Content.IE5\C5I301U7\324123[1].htm Exploit-ANIfile.c
>
> The reason why the above indicates "Delete failed (Clean failed)" is
> because the file wasn't
> allowed to be written to the cache and was blocked.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



 
Reply With Quote
 
 
 
Reply

« vundo fix | jobs »
Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
want to remove pictures during presentation once item identified tazref Microsoft Powerpoint 4 25th Jun 2008 01:35 AM
malware identified but can not remove Roy Windows Vista General Discussion 18 8th Feb 2008 01:30 AM
DSO Exploits Stu Spyware Discussion 3 22nd Aug 2005 06:35 PM
RE: DSO Exploits Engel Spyware Discussion 0 19th Aug 2005 08:16 PM
DOS Exploits =?Utf-8?B?Q2hyaXN0aWUgR2FyemE=?= Windows XP Security 2 10th Jul 2004 04:01 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:36 PM.