Exploit-MSWord.a Real or False Positive

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KirkMango, Aug 6, 2011.

  1. KirkMango

    KirkMango Private E-2

    I am really just looking for information on this one from a very knowledgeable malware expert. I have a very new dell computer with fully updated Windows 7, IE9, and securities run pretty high. I use this computer mainly for writing and editing of my forthcoming book and writing for the Tribune ChicagoNow blog network. I do very little searching on the internet and deal maninly with sites I know and trust (like this one) and answering and writing emails (yes I do get attachments).

    As far as security, I run Mcafee's Security Suite with Firewall, Spam Filter, etc. and have both the free Malwayrebytes scanner and Super Antispyware scanner, which I update and run once to twice a week. These two scanners where the first downloads on the machine after updating Windows 7 and Mcafee.

    I also run a Mcafee scan manually and let it run its scheduled scan weekly. Malwayrebytes and Super Antispyware have never found anything on my computer, nor has Mcafee when I run my manual scans. I also scan any attachments with Mcafee and Malwayrebytes before I open them up and these scans have never found a thing. In addition, I run CCleaner more than once a week to clean things up in temp areas. I am highly attuned to keeping my computer free of junk.

    About a month after my new computer came I took a large Word file and converted it from a 2010 file into an earlier format for my editor. Later that week my Mcafee scheduled scan found and quarentined Exploit-MSWord.a. I promptly deleted it from quarentine and noted where the file was located originally. This is where it gets strange. Here was the path: C:\Users\Kirk Mango\AppData\Local\Microsoft\Office\UnsavedFiles\Working Master Manuscript Edited - Tuesday 7-12-11((Unsaved-301631140143290256)).asd

    I found it strange that this exploit was never found in any other scan and was not indentified until Mcafee ran a scheduled scan and after I had converted the file to an earlier version of Word. When I researched Exploit-MSWord.a it is said to be a Trojan by Mcafee but only Mcafee seems to know about it. Plus, I found it strange that it is located in unsaved files, those files Word would use to go back to if the power went out and you lost the file you were working on or it got corrupted.

    Called Mcafee since I have a new computer and new service with them and they said it was not a false positive and that the scanner had removed it from my machine. Ok, did not seem right especially since it was never found by anything else before in the first month I had the computer, was only found when I converted the file, and was in an unsaved file area.

    Two more months goes by, I run all my normal scans each week using all my updated scanners and nothing, and on an updated version of my book, same file just updated from my editor but that I broke down by chapter and saved as seperate Word files, Mcafee scheduled scan finds the same would be trojan Exploit-MSWord.a. and in the same area: C:\Users\Kirk Mango\AppData\Local\Microsoft\Office\UnsavedFiles\Kirk M((Unsaved-301671311400402224)).asd. I again delete the file from quarantine.

    Again, I find it strange that nothing is found until the file is broken down or converted and Mcafee scheduled scan is the only one that finds this same so called Trojan. This time I call Microsoft, their security division, and they search their database for such a Trojan and say they don't have anything on this. I ask them if they have an online scanner I could use figuring since this thing seems to be only associated with Microsoft Word that something they use to remove Viruses/Trojans would be a good 4th check since I run three other different malware/virus scanners. They send me to their Microsoft Safety Scanner. I run a full scan and nothing is found. I run all my scans again, Malwayrebytes and Super Antispyware and nothing.

    My question is, is this a false positive? Is Mcafee the only scanner or virus program that finds this thing, and only on a scheduled scan, and actually in an unsaved file area for Microsoft Word. Again, no other company seems to know about this Exploit-MSWord.a. Any attachment I get from my editor that I download, or anyone else for that matter is always scanned with an updated Malwayrebytes and Mcafee before it is opened and they have never found anything. What the heck???

    I would like to know more about this thing before I go down the path of trying to remove something that may not really exist.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exploits are not really infections. They are just potential risks that could be taken advantage of ( i.e., exploited), All software programs are frequently updated to remove potential security risks ( exploits ). When you don't update or when you use old versions of software ( or like you did to convert to an earlier version ) you keep the potential security risks around. Are they really problems..... well it depends on your viewpoint. You are at risk of being exploited, but it is not a malware problem and you are not infected just because you have a file or program that "could" potentially be exploited. Thousands of people are running old outdated copies of Windows that have hundreds of security holes. Does this mean they are infected? No, of course not. But they are at risk.

    You should read this: http://www.microsoft.com/technet/security/advisory/960906.mspx

    There are many such notices.

    My advice would be to either use all properly updated software and not old version and do not convert files to be used with old programs. Otherwise ignore the explot because it is not an infection. It is a risk. And it is a low risk ( even McAfee says so : http://vil.nai.com/vil/content/v_141098.htm )
     
  3. KirkMango

    KirkMango Private E-2

    This is why I like coming here when I need a straight answer. Here you have people who actually know what they are doing. Ok, only two more questions if I might Chaslang.

    1. If it is only a security risk than what is Mcafee actually quarentining and what am I deleting from quarintine? Mcafee insists it is a Trojan.

    2. Is it OK to just keep my Malwarebytes free scanner (updated daily by me), Super Antispyware scanner (updated daily by me), and CCleaner (latest verison) on my computer in my spyware tools folder? Mcafee tech is telling me I should not have them on as they cause problems for Mcafee. When I try to explain to them that they are only the scanner that does not run in the background and that they are only used to scan they don't seem to understand.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are quarantining a file which they believe shows signs of the exploit that they are mentioning. If it were a trojan, they would be calling it a trojan like they do with hundreds of other "REAL" trojans. By their own definition, this file exploit is a low risk item and per their own information, a low risk item is
    The above is quoted from http://www.mcafee.com/us/mcafee-labs/resources/vulnerability-assessment.aspx

    So if it was really a trojan and really a problem of concern, it should not be listed as a low risk exploit. ;)

    Yes they are fine to keep. Note: CCleaner is not an antispyware program at all.
     
    Last edited: Aug 9, 2011
  5. KirkMango

    KirkMango Private E-2

    Thanks for your help and information. Major Geeks is the best!!!

    Oh, and I know CCleaner is just a cleaning/maintanance type program, I just keep it in the same folder as my two scanners.

    Best,

    Kirk
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds