Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

Question

Gardenweb and Exploit

Feb 22, 2012 12:10AM PST

I keep getting virus warnings when I go on gardenweb. It says something about "exploit". Every click will bring up another warning and ask for an action (remove, vault, etc.). No one else on gardenweb is getting warnings. I checked the AVG user forum and there are no mentions there (although there is some kind of problem there, as it is too slow to use), either. I checked with Microsoft and added a couple of updates, just to make sure that wasn't a problem, but I still can't use Gardeweb.

What can I do? You would think if there really was a virus, others would be getting a warning, too.

bkay

Discussion is locked

- Collapse -
Answer
Gardenweb
Feb 22, 2012 3:19AM PST

Hello bkay,

I have checked Gardenweb.com and it appears to be clean without any AVG detections.

It is possible that the infection is present on your computer.
Please provide us with AVG scan results export and both GMER outputs.

Thank you

- Collapse -
Here's the scan result..
Feb 22, 2012 8:31AM PST

What's GMER? I could not find it in help. If it has something to do with gaming, I don't do that.

Scan "Whole computer scan" completed.
No infection was found during this scan
Folders selected for scanning:;"Whole computer scan"
Scan started:;"Wednesday, February 22, 2012, 5:58:08 PM"
Scan finished:;"Wednesday, February 22, 2012, 6:09:40 PM (11 minute(s) 31 second(s))"
Total object scanned:;"1246661"
User who launched the scan:;"Barbara"


As of 6:30, I'm still getting the warnings. History:

Resident Shield detection
Infection;"Object";"Result";"Detection time";"Object Type";"Process"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0J80X4K3\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/22/2012, 6:26:22 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0J80X4K3\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/22/2012, 9:17:39 AM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W1TXIA3Y\forums_gardenweb_com[1].js";"Object is inaccessible.";"2/22/2012, 9:17:39 AM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W1TXIA3Y\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 6:18:08 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0J80X4K3\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 2:36:17 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1M2PWGSZ\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 2:36:01 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0J80X4K3\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 2:34:11 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0J80X4K3\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 2:29:37 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
Virus found Script/Exploit;"c:\Users\Barbara\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NJKU5IP0\forums_gardenweb_com[1].js";"Moved to Virus Vault";"2/21/2012, 2:19:51 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"

- Collapse -
Other people are getting them too
Feb 22, 2012 8:35AM PST

I just checked my gardenweb messages and other AVG users are getting them too. One in the UK. One in NC. One AVG user is not getting them, but he uses firefox with ad block. McAfee users are not getting them.

bkay

- Collapse -
Possible false detection
Feb 22, 2012 11:40PM PST

Hello bkay,

I have induced the detection in my environment and passed the information to our viruslab specialists.
Detection is most likely false positive and should be removed from our virus databases shortly.

Thank you