Computing.Net > Forums > Security and Virus > Acro Reader 7 vulnerability?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

Acro Reader 7 vulnerability?

Reply to Message Icon

Name: 23456256
Date: December 5, 2005 at 15:16:36 Pacific
OS: xp, sp2
CPU/Ram: 2ghz, 1gb
Comment:

Adobe Reader 7 vulnerability?

what's your opinion?

I like win.explorer to be lightweight (is v. fat after XP SP2!). So I was annoyed recently when just by rolling the mouse over list of files in explorer, ssm reported:
svhost.exe wants to run AcroRd32Info.exe
call to API "create process"; parameters were:
G:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe /PDFShell -Embedding.

Adobe Reader 7 is calling an exe without my permission??? This could be a huge security lapse, no?

I guess this is some pre-fetch garbarge from Adobe no doubt. (I don't even have exlorer set to show the "thumbnails" or "minature view" bollox)

I searched the internet for this and found v. little.

How do I stop this at source? I can delete the AcroRd32Info.exe but then explorer complains it can't find the file. The dll's assoc. with AcroRd32Info.exe are:

276 ntdll.dll, kernel32.dll, MSVCR71.dll,
BIB.dll, AcroRd32.dll, AGM.dll, USER32.dll,
GDI32.dll, MSVCP71.dll, CoolType.dll,
ADVAPI32.dll, RPCRT4.dll, SHELL32.dll,
msvcrt.dll, SHLWAPI.dll, ole32.dll,
VERSION.dll, COMCTL32.dll, OLEAUT32.dll,
ACE.dll, WINMM.dll, SETUPAPI.dll,
CLBCATQ.DLL, COMRes.dll, xpsp2res.dll,
msi.dll, USERENV.dll, SXS.DLL


I used Uninstaller (from ashampoo - it's crap, I know but stripped it does the job!) for a before and after install comparison and took a look, but I know too little about the registry to understand what the critical keys are that migght assign adobe's new dll's to win.explorer.

Be very interested if anyone else has seen this, is concerned about this.

Ian




Response Number 1
Name: Derek
Date: December 5, 2005 at 16:34:07 Pacific
+1
Reply:

Not so much advice but a thought (bear in mind that I'm mainly a W98SE user):

What I've often done in these situations is produce a file in NotePad with just the word dummy in the text. I've renamed it to the .exe file that is troublesome.

You then rename the "problem .exe" to .ex- (so that you can get it back if necessary) and put the dummy in it's place. This fools the system (well it fools W98SE anyway) that the file is still there. It obiously can no longer act tho.

DerekW


Reply to Message Icon

Related Posts

See More


AIM Christmas Card Virus W32.Conycspa.G@mm virus



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Google Ads



Results for: Acro Reader 7 vulnerability?

this one is an annoying little troj www.computing.net/answers/security/this-one-is-an-annoying-little-troj/20467.html

Post-Spyaxe problems www.computing.net/answers/security/postspyaxe-problems/17458.html

aim myspace virus(i think its gone) www.computing.net/answers/security/aim-myspace-virusi-think-its-gone/20590.html