Wilders Security Forums  

Go Back   Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 24th, 2005, 11:35 PM
Extremely Unhappy
 
Posts: n/a
Angry Bloodhound.Exploit.6

I just downloaded your SpyBlaster freeware, and when I selected update, I was immediately infected with the Bloodhound.Exploit.6 virus! My virus protection attempted to stop it, and delete it, but couldn't. I was not doing anything but updating your software when this took place.

I found the virus at: C:\WINNT\Temp\~428A016C.tmp, but I couldn't delete it. I went to the MS site and d/l the patch, but by the time I did that, my Outlook was already corrupted, and I started receiving errors from IE. I had to reinstall IE and run the patch immediately after. I also deleted the Temp folder (which I hope wasn't a bad thing). Then I logged off and back on, and the file was gone.

This is a heads up to the software owners as well as the consumers. It took me 3 hours to clean this horrendous thing off my computer (due to all the errors received, the slowness of the system once it was infected, the IE locking up, etc. etc.). I did not expect a "recommended" software that prevents spyware to contain a virus, and it rather p'd me off.
  #2  
Old January 25th, 2005, 12:05 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

you might check out the info at the link
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #3  
Old January 25th, 2005, 12:16 AM
divedog's Avatar
divedog divedog is offline
Frequent Poster
 
Join Date: Jun 2004
Location: Seabeck WA
Posts: 265
Default Re: Bloodhound.Exploit.6

NORTON??
  #4  
Old January 25th, 2005, 12:19 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

It is detected by norton, the link is their info and cleaning page.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #5  
Old January 25th, 2005, 12:21 AM
divedog's Avatar
divedog divedog is offline
Frequent Poster
 
Join Date: Jun 2004
Location: Seabeck WA
Posts: 265
Default Re: Bloodhound.Exploit.6

Sorry I should have been more clear I was asking if he was running Norton.
  #6  
Old January 25th, 2005, 12:22 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

yes he was
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #7  
Old January 25th, 2005, 12:26 AM
divedog's Avatar
divedog divedog is offline
Frequent Poster
 
Join Date: Jun 2004
Location: Seabeck WA
Posts: 265
Default Re: Bloodhound.Exploit.6

Take a look at this.
http://www.sophos.com/virusinfo/hoaxes/bloodhound.html
  #8  
Old January 25th, 2005, 12:28 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

That is why the recomended action is to get the microsoft patch to prevent this
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #9  
Old January 25th, 2005, 12:41 AM
divedog's Avatar
divedog divedog is offline
Frequent Poster
 
Join Date: Jun 2004
Location: Seabeck WA
Posts: 265
Default Re: Bloodhound.Exploit.6

Quote:
Originally Posted by bigc73542
That is why the recomended action is to get the microsoft patch to prevent this

I agree. It just seems a bit dubious. I have used Spyware Blaster for quite some time and have never had a problem with updates. It would seem that Norton thought the update was a virus. I would try one of the on line scanners for a second opinion and to make sure all is well.
  #10  
Old January 25th, 2005, 12:45 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

Norton was detecting an adware trojan. but with the patch you don't get that particular trojan at all. Bloodhound is just the name that norton gives it
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #11  
Old January 25th, 2005, 06:17 AM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,879
Default Re: Bloodhound.Exploit.6

Quote:
Originally Posted by Extremely Unhappy
I did not expect a "recommended" software that prevents spyware to contain a virus, and it rather p'd me off.

Hi,

SpywareBlaster doesn't contain a virus.

What you may have seen is your anti-virus program's "auto-protect" option picking up on a pre-existing file because access of your temporary directory was initiated for some reason or another. (I've also seen this happen seemingly randomly.)

It could have also been a false positive.

I hope this helps clear things up a bit.

Best regards,

-Javacool
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #12  
Old January 25th, 2005, 01:43 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: Bloodhound.Exploit.6

Sometimes a little investigation goes a long way
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #13  
Old January 25th, 2005, 01:48 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Bloodhound.Exploit.6

I figured that everyone knew that spywareblaster would not have a virus, I was trying to show that it was a symantec problem. They admit that without the MS patch their av will detect this. Not just in spywareblaster but just about anything

bigc
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
 

Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:53 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums