in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Adobe Flash Player False Positive?

Last post 07-03-2009 11:13 AM by nomuus. 7 replies.
Page 1 of 1 (8 items)
Sort Posts: Previous Next
  • 04-16-2009 6:25 PM

    Adobe Flash Player False Positive?

    instead of updating our Flash Player all the time, we have opted to remove/uninstall the software from machines that don't require it (no internet connection).

    however, when i scan, i get this finding:  under the tested value, the registry key does not exist on the target PC.

    Description: Success
    Tested Value: CMP,T,ECL,SOFTWARE\Microsoft\Active Setup\Installed Components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
    Found Value:

    thank you.

  • 04-16-2009 6:40 PM In reply to

    Re: Adobe Flash Player False Positive?

     Did you uninstall the Flash Player using Adobe's uninstaller tool?

    http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_14157&sliceId=2

    I know that Flash is a pain in the *** to uninstall and does not completey uninstall itself properly using the Add/Remove Programs function in windows most of the time.  I have had similiar issues in the past until I started using their tool.

    This may not even help your situation, but it is worth a try.

  • 04-16-2009 6:48 PM In reply to

    Re: Adobe Flash Player False Positive?

     yup.  used the tool.  after i used the tool, i had different finding...i'll post that one later :-)

    would rather solve this one first.

    i have even went as far as reloading the flash then uninstalling it again.  no joy.

    not sure what to do.  i have MANY PCs like this too.

     

  • 04-16-2009 7:02 PM In reply to

    Re: Adobe Flash Player False Positive?

     Interesting ...

    What OS are you running?

    What version of Flash are you having these issues with?  (IE ActiveX or Firefox packaged version?)

         We may have to wait until one of the eEye guys can assist with this one.  I am not the best with the Retina stuff.

  • 04-16-2009 7:46 PM In reply to

    • Ozone
    • Top 25 Contributor
    • Joined on 10-12-2007
    • Posts 25

    Re: Adobe Flash Player False Positive?

    Have you tried the Adobe Flash Player installer?

    http://www.adobe.com/shockwave/download/alternates/

     

    Regards.
    Ozone
  • 06-04-2009 7:38 AM In reply to

    Re: Adobe Flash Player False Positive?

     This is because it was delivered starting with Windows XP.

    To Fix:

    Go to the following link and download the correct update for your operating system.

    http://www.microsoft.com/technet/security/bulletin/MS06-069.mspx

    Once this has been installed you may be hit for a different Flash Player issue.

    Remove the following file:

    %System Drive%\Windows\System32\Macromed\Flashplayer\Flash6.ocx

     

  • 06-22-2009 9:34 AM In reply to

    Re: Adobe Flash Player False Positive?

    I found this file in \Windows\System32\Macromed\Flash\Flash6.ocx

    As admin I could not delete the file even with /f.

    I could rename it however.  MD5...: b729ba1592acacb47f2b06dd3d5753fa does not show as an infected file.

    I presume I'd have to bring the system down to properly delete the file or killbox it.

    JRF
  • 07-03-2009 11:13 AM In reply to

    Re: Adobe Flash Player False Positive?

    rcarvalh:

    instead of updating our Flash Player all the time, we have opted to remove/uninstall the software from machines that don't require it (no internet connection).

    however, when i scan, i get this finding:  under the tested value, the registry key does not exist on the target PC.

     

    Description: Success
    Tested Value: CMP,T,ECL,SOFTWARE\Microsoft\Active Setup\Installed Components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
    Found Value:

    thank you.

     

    The audit you are referring to is for a Microsoft provided update for Adobe Flash that came preinstalled on Windows.  I believe since the time of your post that the audit has been updated.  Such is sometimes the case with audits as new information becomes available or as time progresses.  Send me a PM if this is still an issue and I will give you some one on one help.

     

Page 1 of 1 (8 items)
© 1995 - 2009 eEye Incorporated