Author Topic: Avast caught it  (Read 4175 times)

0 Members and 1 Guest are viewing this topic.

darth

  • Guest
Avast caught it
« on: September 14, 2009, 02:07:39 AM »
While reading the New York Times on line, Twice in two days it caught the following "js:redirect-ah[trj]". The paper run a story on the malware.

See http://mediamemo.allthingsd.com/20090913/home-delivery-the-new-york-times-serves-up-some-malware/.

Thank you Avast.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast caught it
« Reply #1 on: September 14, 2009, 02:24:45 AM »
Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Maybe you could contact its webmaster.

Also, please, check if there are infected gif images (resolved as infected server generated messages): http://forum.avast.com/index.php?topic=45658.0

Please, edit the links to not-live ones (change http for hxxp, for instance or add spaces between the url).

Check here how to clean and make a website secure.

Quote
The vast majority of malware today is distributed over the web, mostly by means of hacked (otherwise legitimate) sites. The attacker usually injects malicious some scripts into some (or all) pages on the site, waiting for an unsuspecting user to visit the site and possible infect his/her machine.

And this is where avast’s detection capabilities really excel. Its abilities to detect these web-based malicious scripts are second to none, and thanks to the Web Shield and Script Blocking providers, they are used exactly when needed, doing an excellent job stopping the web-based malware right on the entry point.
The best things in life are free.

darth

  • Guest
Re: Avast caught it
« Reply #2 on: September 14, 2009, 02:59:01 AM »
According to the story in the NY Times, to the best of my understanding, the site was hacked.

I realy don't know much about iframes or stuff like that.  Thanks for the suggestion, to notify the Web Master, although since they published the malware article, in thier online addition; they have apparently rectified the matter.

It has not happen  again  so far.

YoKenny

  • Guest
Re: Avast caught it
« Reply #3 on: September 14, 2009, 10:57:22 AM »

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Avast caught it
« Reply #4 on: September 14, 2009, 06:33:00 PM »
NYT apologizes http://www.nytimes.com/2009/09/13/business/media/13note.html?hp

FWIW, I visited NYT yesterday and received no alarm (and no redirection, pop up, or infection) using Firefox with NoScript and AdBlock Plus (NYT was not whitelisted in these extensions).  Probably, this requires JavaScript to work???

AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast caught it
« Reply #5 on: September 14, 2009, 07:26:16 PM »
If the script is on the page, it doesn't have to run for avast to actually detect it. So even with firefox & noscript, avast should alert even if the redirect script isn't run.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Avast caught it
« Reply #6 on: September 14, 2009, 08:20:45 PM »
If the script is on the page, it doesn't have to run for avast to actually detect it. So even with firefox & noscript, avast should alert even if the redirect script isn't run.

Interesting, so that means that the site must have been sanitized before I visited.  These fake antivirus programs have been around for a while.  My sister-inlaw's computer was infected about 2 weeks ago, from some unknown source.  It had AVG 8.5 on it.  They surfed as Admin, sadly.

By the time I got to it yesterday, the machine was virtually unusable.  I safe-booted, downloaded Malwarebytes and cleaned a ton of stuff, running Malwarebytes 3 times rebooting into safe mode between each time.  Did the same with Spybot Search & Destroy which found a few more.  Uninstalled AVG via Add/Remove.  On reboot, ran AVGremover.  I then installed Avast Home for her, registered it and updated the definitions.  Ran a full Avast scan and it found a couple of nasties in the Restore files and quarintined them.  Set up limited WinXP Pro user accounts for them to surf with, and a new admin account with passwords on all.  Avast has it's own password added.  By then it was late.  When I get back over there, I'll eliminate all the Windows Restore files and then create a new restore point.  I also will update from WinXP Pro SP2 to SP3.

It seemed fine when I left, but is there anything I'm missing?
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast caught it
« Reply #7 on: September 14, 2009, 09:01:04 PM »
Effectively it would have to be cleaned or avast would alert, simple as that, as its pro-active protection may stop the complete page loading if it is part of the main page code.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Avast caught it
« Reply #8 on: September 14, 2009, 09:45:27 PM »
Thank you, David. :)
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast caught it
« Reply #9 on: September 14, 2009, 09:49:25 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security