Jump to content

Notification Centre Protection issue resolution options


JoBl

Recommended Posts

I have a protection issue in my notification centre (Kaspersky Anti-Virus) which says :

HEUR:Exploit.MSOffice.Generic detected and then gives the pathname for the object. The options listed when I click the Resolve button are:

Add to exclusions

Ignore

Open containing folder

View report

Learn more

If Ignore means to leave the object on my computer, and Add to Exclusions does the same, then how do I remove the malware or whatever it is? If it has already been removed by the scan and this is just a report of it, then how do I clear the warning message?

Hope someone can help!

 

 

 

 

Link to comment
Share on other sites

Hello  @JoBl,

Welcome!

🛑HEUR:Exploit.MSOffice.Generic (Kaspersky), Exploit:O97M/CVE-2017-11882!rfn (Microsoft)🛑

KAV version & patch(x)? Is KAV updated to the latest 20.0.14.1085(f)?⬅

So we can guide you, please provide KAV Report:  open KAV, select More Tools, select, Reports, select Detailed Reports, leave ALL Events as default,  select 24hrs, select Export, save report as a .txt file, &  📎 attach 📎 to your reply?

Thank you

Kaspersky Anti-Virus 20.0.14.1085 release notes, Patches A – F

Vulnerability Report: List of Advisories

Link to comment
Share on other sites

Sorry. I have redone the detailed report for All Events, for the last 24 hours and also for the last 30 days. I did the latter because the date the detected object was reported was 17th November and I have been wondering what to do with it since then. 

As it is not repeated each day since, does that mean that it has been removed?  And if so, then which option is the correct one to take so that it stops showing as an unresolved item?

Thanks for helping me with this - hope I have produced the correct reports for you.

BTW - When I take the More Tools tab, there is no reporting option in the pulldown, so I accessed the detail reports via the Notification centre.

 

Cheers

Jo

 

Link to comment
Share on other sites

 

I have KAV premium I guess, as the Reports option is a button on the main application window. And the More Tools menu does not have a reporting option in this case.

So maybe give people both pathways to the reports, as I guess they will have one or the other! :)

Looking forward to hearing back from you.

Cheers

Link to comment
Share on other sites

Hello  @JoBl,

Thank you for replying🙏

All good👏 , you managed to extract the data, despite my clumsy efforts 😥 .
I will keep your information in mind, for my next victim😉

  • I’ll post back after reviewing the data.

In the meantime have you read the references above: 

HEUR:Exploit.MSOffice.Generic (Kaspersky), Exploit:O97M/CVE-2017-11882!rfn (Microsoft) ? 

Thank you

 

Link to comment
Share on other sites

Hello  @JoBl

Thank you for the image.

Please do the following steps:

1  Create a System Restore Point.
2  Google Chrome, Reset to default  chrome://settings/reset, select Restore settings to their original defaults, select Reset Settings, allow process to complete, exit Chrome, do not restart.
3  KAV Clear Reports - (should be Settings, Additional, Reports & Quarantine

4KAV Export settings & Restores settings:

🅰 Select Settings, select Manage settings, select Export settings, save .cfg file
🅱 Select Restore settings, acknowledge UAC popup, allow process to complete.

5  Windows File Explorer:

  1. Clear C:\Windows\Temp, note: there may be some files/folders requesting “Admin permission” to delete, grant the permission, additionally, there may be some file/folders “in use”, select  “OK” or “Skip”
  1. Clear C:\Users\YOURNAME\AppData\Local\Temp, note: there may be some files/folders requesting “Admin permission”, grant the permission, additionally, there may be some file/folders “in use”, select  “OK” or “Skip.”
  1. Repeat Step 5b. if there are any other (Windows) User accounts. 

6  Clear/empty Recycle Bin.

7  Shutdown computer using Shutdown, not Restart, when computer is fully OFF, power on, login.

8  Start KAV only (no other applications)

  1. Select Settings, select Security Level, select Maximum Security Level
  2. Run KAV manual Database Update, allow it to complete. 
  3. Run KAV Vulnerability Scan, allow it to complete. 
  4. Run KAV Full Scan, allow it to complete.
  5. Start Chrome, do not use, start only, start Windows File Explorer, go to: C:\Users\YOURNAME\AppData\Local\Google\Chrome\User Data\Default\Cache - screen print & post back image please? 
  6. Monitor issue. 

Note1:​​​​

After a monitoring period of your choosing, you may wish to reset KAV Security Level, that’s perfectly fine, select whatever Security Level you determine is suitable. 

  • If the issue returns, please let me know?

Thank you.

 

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...