Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

9873

June 17th, 2012 12:00

Has anybody heard of Exploit:JS/Blacole.FZ? Is it a Virus or Malware?

Hi

I just did a full sacn on my MSE.

It has discovered the above and displayed as severe and given me the option to remove, which I have done.

Would that be enough and has anybody else heard of this ?

 

 I also ran the Malwarebytes Anti-Malware on demand [Free] scan and has been reported as clean. 

Regards

 

 

20.5K Posts

June 17th, 2012 13:00

Hi snowshine,

To answer your question: "Is it a Virus or Malware?"

It's really neither, but an exploit. Detection for this was created recently.

"JS/Blacole is a detection for a component of the Blackhole exploit kit - a kit used by attackers to distribute malware. Attackers install the kit onto a server, and then when you visit the compromised server, the kit attempts to exploit various, multiple vulnerabilities on your computer in order to install malware. For example, if you browsed a compromised website containing the exploit pack using a vulnerable computer, malware could be downloaded and installed onto your computer.

Typically, the Blackhole exploit kit attempts to exploit vulnerabilities in applications such as Oracle Java, Sun Java, Adobe Acrobat and Adobe Reader.

For more information on this exploit kit, and steps you can take to avoid being compromised, please see the detailed Blacole description, elsewhere in our encyclopedia..."

From here:

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=JS/Blacole
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Exploit%3AJS%2FBlacole.FZ

It was in your Temporary Internet Files, so removing it via MSSE or deleting your TIF files would have been enough -- until you visit the webpage in question again. If malware had been downloaded and installed, MBAM probably would have found it, or MSSE would have alerted you about additional problems.

1 Rookie

 • 

5.8K Posts

June 17th, 2012 14:00

 

Could this be a false positive detected by MSE?
http://r.virscan.org/dd8e1bc98be41a326a0e1e29a038d7e5

1.1K Posts

June 17th, 2012 14:00

Very helpful as ever and thank you very much.

Regards

No Events found!

Top