Author Topic: "JS:Pdfka-DV [Expl]" has been found  (Read 4724 times)

0 Members and 1 Guest are viewing this topic.

Robertjj

  • Guest
"JS:Pdfka-DV [Expl]" has been found
« on: June 11, 2009, 07:58:21 PM »
I did a scan on a computer and the result said:  6/11/2009 10:57:01 AM   scan   3640   Sign of "JS:Pdfka-DV [Expl]" has been found in "\\Anniet2\c$\Documents and Settings\annie\Local Settings\Temp\plugtmp-2\plugin-pdf.php" file.  What does this mean?

micky77

  • Guest
Re: "JS:Pdfka-DV [Expl]" has been found
« Reply #1 on: June 11, 2009, 09:40:13 PM »
I think it may be  a serious security flaw, by having an outdated Adobe. Do you have adobe reader ? What version.Are you experiencing problems with your pc

Robertjj

  • Guest
Re: "JS:Pdfka-DV [Expl]" has been found
« Reply #2 on: June 11, 2009, 10:15:33 PM »
Can I just delete this file or does this indicate something bad has been installed?

micky77

  • Guest
Re: "JS:Pdfka-DV [Expl]" has been found
« Reply #3 on: June 11, 2009, 10:40:45 PM »
Why don't you navigate to the file plugin-pdf.php, send it to VT for analysis, then copy/paste the results. If you are infected, you will not be able to simply delete.

http://www.virustotal.com/

You did not say what version,if any, you have of Adobe

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: "JS:Pdfka-DV [Expl]" has been found
« Reply #4 on: June 12, 2009, 12:12:23 AM »
For these cases there is Secunia PSI - http://secunia.com/PSISetup.exe
This program can be used to regularly check on your third party software, e.g. adobe, to see whether you have the latest version and all patches,
Could be via an iframe in the html loading the .pdf file or even allowing the javascripts and Mime and activeX for the sites will allow the silent download of a .pdf file.

Things to do besides disabling the mime, vbs, activeX and javascripts for global surfing, use Firefox browser with NoScript installed.
And disabling the use of iframes inside of the browser itself. This can be done in the Internet Explorer for just the Internet Security Zones in either the Tools of the IE or the Internet Options in the Control Panel or easily within the Opera browser( see http://www.aimwell.org/Help/Buttons/buttons.html for the "iframe checkbox" for use on the Opera's toolbar).

Also make sure Windows is fully patched and updated with all ServicePacks installed.
After Adobe has been updated, please disable the use of Javascripts inside of the Adobe as an extra measure.

Files located in the Temporary Internet Files folder can be deleted by the history of the Internet Options or by a cleaner such as CCleaner, ATFCleaner, ClearProg.

If anything else please post a HijackThisLog.txt as an attached txt.file to your next posting,
you can install HJT from here: http://www.filehippo.com/download_hijackthis/download/58170ee6e58bba306c943f5b6d745c99/

polonus

« Last Edit: June 12, 2009, 12:14:25 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!