Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows VistaWindows XPWindows MeWindows 98Windows 95Virtual PCInternet ExplorerOutlook ExpressWindows MediaSecurity
Related Topics
MS Server ProductsMS OfficePC HardwareMore Topics ...

Windows Forum / Security / Internet Explorer Security / August 2008

Tip: Looking for answers? Try searching our database.

Virus attacks "unknown vulnerability" in IE7?

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Dale - 28 Aug 2008 03:58 GMT
I run a pretty tight ship when it comes to updates.  I have a WSUS server and
most of my PCs update completely automatically, including the PC I am writing
about today.  It is fully updated with all availble security updates as are
all Microsoft software products.  That does't exclude non-Microsoft products
as a security hole, of course.

I started getting ads popping up in IE windows so I got pretty suspicious.  
I ran a scan with my AV (F-Prot) with no viruses found.  I had, though,
recently had a few viruses found as I surfed the web site for an
international manufacturer for a hobby. Remember a found virus is a stopped
virus; it's the unfound ones you have to worry about.  I reported the virus
to the company and it appears - from others I have talkedto - that they
cleaned it up.  I haven't been back to the site.  The viruses found on the
site were js_psyme and html_iframe.  Both of these viruses attacked the ADODB
stream vulnerability from a couple years back.  Since that opening has long
been fixed on my PCs, I didn't worry those viruses being found.  

Suddenly, yesterday, I started gettng these popup ads.  I ran Trend Micro
HouseCall and that found another virus, presumably missed by F-Prot, called
JS_Small.ftj.  The data from Trend Micro about this virus says:

[Quote]It takes advantage of an unknown vulnerability in Internet Explorer
to allow to download possible malicious files on the affected machine. It
does this by using the vulnerable CLSIDs from the affected system.[End Quote]

So what is up with an "unknown vulnerability" in IE7?  I know there are
probably dozens or hundreds of unknown vulnerabilities in IE7 but since the
virus report on this has been out since May 8, 2008, how is this still
unknown and when will there be a patch?  I know that it is a rhetorical
question but I still wanted to raise it.
Frank Saunders MS-MVP IE,OE/WM - 28 Aug 2008 15:43 GMT
>I run a pretty tight ship when it comes to updates.  I have a WSUS server
>and
[quoted text clipped - 37 lines]
> unknown and when will there be a patch?  I know that it is a rhetorical
> question but I still wanted to raise it.

Do a thorough check for malware, following all of the steps at one of these
Web pages.
Help with malware:
All  MS-MVP Sites.
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://www.elephantboycomputers.com/page2.html#Removing_Malware
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/darnit.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm

Unexplained computer behavior may be caused by deceptive software.
http://support.microsoft.com/kb/827315

So How Did I Get Infected Anyway?
For quite a few people it's by installing programs like Messenger Plus,
whose ads for malware don't identify the malware as such and try to convince
you that you owe it to the author.  See also:
http://www.wilderssecurity.com/showthread.php?t=27971
Don't ever do a "default" install of anything.  Always choose Custom and see
what else is being carried along.  Don't install any extras you're not sure
of.

Signature

Frank Saunders MS-MVP IE,OE/WM
Do not reply with email

 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.