Virus Encyclopedia

Computer Virus Encyclopedia

Exploit.HTML.Ascii.b

Alert Level : Low
Discovered: Jan 10 2008
Tag:
Discoverer and Source: http://www.kaspersky.com/

Malware Behavior and Technical Description

This exploit uses a vulnerability in Internet Explorer (CVE-2006-3227) to run on the victim machine. It is an HTML page. It is 3616 bytes in size. It is not packed in any way.

Payload

This malicious program exploits a vulnerability which enables a remote malicious user to modify the appearance of pages displayed in Internet Explorer and to evade content filtering due to incorrect interpretation of 8-bit ASCII symbols.

Without the knowledge of the user, the script downloads another script from the following link:

http://count*****.com/click.aspx?id=234594407

Removal Exploit.HTML.Ascii.b instructions:

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original exploit file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following file: %Temp%\svchost.exe
  3. Install Internet Explorer updates.
  4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

Need help? Live computer support via remote at SupportSpace.Help with printer problems, windows, hardware, software, spyware removal and more. - Go Now!

Site Map
About Us