PDA

View Full Version : McAfee detected 'Exploit - MhtRedir.gen'


T772
December 21st, 2005, 10:14 PM
Hi,
while i was looking for some infomation on this file I found on my system called 'C07ft5Y' - I seem to have been infected with this exploit as i got a pop-up saying McAfee had deleted (Exploit - MhtRedir.gen) this in >C:\Documents and Settings\Owner\Local or this :\Documents and Settings\User\Local Settings\ not sure which. Link for virus;-

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101033

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101033

But I did a full scan of my system and it came up clean, then I did a online scan at KAS and nothing. The sites I was looking at were winguides.com, go2share.net and pcguide.com, so maybe these sites could be dangerous not sure? IT was very strange, as I did a full scan yesterday and found nothing, but updated today with the latest DAT file, so I was wondering if this could of been on my system for a while any ideas? BUT if i have had an exploit on my system KAS would of picked it up a while ago?

I would really please like some advice on this matter.

Anyway the good news is that i did find some information on that file 'C07ft5Y' at this site >http://help.lockergnome.com/index.php?showtopic=9961

Thanks for any help,

kind regards

Tom

bigc73542
December 21st, 2005, 10:20 PM
more info Here (http://www.spywareinfoforum.com/index.php?showtopic=53196) it looks as if it is a needed file by several different apps.

T772
December 21st, 2005, 10:33 PM
-{ Quote: "more info Here (http://www.spywareinfoforum.com/index.php?showtopic=53196) it looks as if it is a needed file by several different apps." }-Thanks for the info on 'C07ft5'. I was kinda more concered on what McAfee reported and deleted though. Thanks thou BigC.

T

bigc73542
December 21st, 2005, 10:36 PM
here is what Panda AV has to say about the exploit Here (http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=50565)

T772
December 21st, 2005, 10:42 PM
-{ Quote: "here is what Panda AV has to say about the exploit Here (http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=50565)" }-
Hi, BigC so this is quite an old Exploit then 'April2004', so if it had been on my system prior to today it would have most likely been picked up by my AV or even AT, so should I worry about this?

Regards T

bigc73542
December 21st, 2005, 10:47 PM
I would make sure that you have the MS updateHere (http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx) mentioned in the Panda Info and then I would run the panda online scan and see if it picks up the exploit or not if not it could be a false positive on mcafees part. If Panda doesn't pick it up run mcafee again and see if it alerts on it again. If so You might want to run Ewido (they have a free trial) and if it is still there ewido should alert on it and and be able to take care of it.

T772
December 21st, 2005, 10:52 PM
-{ Quote: "I would make sure that you have the MS updateHere (http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx) mentioned in the Panda Info and then I would run the panda online scan and see if it picks up the exploit or not if not it could be a false positive on mcafees part. If Panda doesn't pick it up run mcafee again and see if it alerts on it again. If so You might want to run Ewido (they have a free trial) and if it is still there ewido should alert on it and and be able to take care of it." }-I think its gone, But I will scan with Ewidomost likely do another online scan and see what happens, I owe you one, Thanks T

bigc73542
December 21st, 2005, 10:54 PM
I just hope your problem is gone ;)