How to get rid of Exploit Virus VLm-6

R

rich

My AVG anti virus program found the exploit virus but I cannot seem to
get rid of it. It would not heal. I put it in the virus vault and
deleted it. When I ran the AVG again it came up clean but the next day
it was back again.

Thanx in advance for any help.

Rich
 
D

David H. Lipman

From: <[email protected]>

| My AVG anti virus program found the exploit virus but I cannot seem to
| get rid of it. It would not heal. I put it in the virus vault and
| deleted it. When I ran the AVG again it came up clean but the next day
| it was back again.
|
| Thanx in advance for any help.
|
| Rich

Exploits are not viruses. Exploits may install malware such as viruses and trojans.

Please supply the EXACT message(s) or log extracts.
 
R

rich

From: <[email protected]>

| My AVG anti virus program found the exploit virus but I cannot seem to
| get rid of it. It would not heal. I put it in the virus vault and
| deleted it. When I ran the AVG again it came up clean but the next day
| it was back again.
|
| Thanx in advance for any help.
|
| Rich

Exploits are not viruses. Exploits may install malware such as viruses and trojans.

Please supply the EXACT message(s) or log extracts.

C:\Documents and Settings\Local Settings\Temporary Internet
Files\Content IE5\7ZEU2oAY\new(1)htm

Result: Exploit virus.

Rich
 
D

David H. Lipman

From: <[email protected]>

|
| C:\Documents and Settings\Local Settings\Temporary Internet
| Files\Content IE5\7ZEU2oAY\new(1)htm
|
| Result: Exploit virus.
|
| Rich

Well it is NOT a virus.

It is a HTML file in the IE caches that uses Exploit code.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 
M

MZB

Rich: Have you solved the problem??

I seem to have the same problem as of today.

I put it in the Virus Vault and I am hoping it doesn't come back!!

Mel
 
R

rich

From: <[email protected]>

|
| C:\Documents and Settings\Local Settings\Temporary Internet
| Files\Content IE5\7ZEU2oAY\new(1)htm
|
| Result: Exploit virus.
|
| Rich

Well it is NOT a virus.

It is a HTML file in the IE caches that uses Exploit code.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *

Well I went through this whole process which took several hours. The
exploit bugger returned after the initial scan and cleaning said that
it was gone. It was gone for a day and then returned. Now what?

I tried to send it by e-mail to virus total but got error message
saying that I needed to check my temporary file setting.

Rich
 
D

David H. Lipman

From: <[email protected]>


|
| Well I went through this whole process which took several hours. The
| exploit bugger returned after the initial scan and cleaning said that
| it was gone. It was gone for a day and then returned. Now what?
|
| I tried to send it by e-mail to virus total but got error message
| saying that I needed to check my temporary file setting.
|
| Rich

If it returned, then you most likely went back to a "bad" and malicious web site that caused
it to be cached.

Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete files

Re-scan the computer using the latest signature file.

Be careful of what sites you visit.
 
R

rich

From: <[email protected]>


|
| Well I went through this whole process which took several hours. The
| exploit bugger returned after the initial scan and cleaning said that
| it was gone. It was gone for a day and then returned. Now what?
|
| I tried to send it by e-mail to virus total but got error message
| saying that I needed to check my temporary file setting.
|
| Rich

If it returned, then you most likely went back to a "bad" and malicious web site that caused
it to be cached.

The funny thing is that I don't even use IE as a browser. I use
FireFox.
Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete files

OK. I will try that. Thanx.

Rich
 
M

MZB

Rich:

I am going through a similar situation (well, I don't know if it has
reappeared yet, but the exploit started yesterday -- read my lengthy thread
with David).

However, AVG popped up when I was on a site I rarely visit: youtube.com

This is a very popular site and I wouldn't have expected a problem.

Just wondering if you have any suspicion of what site you may have visited?

Mel
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top