Author Topic: Avast found a Trojan Horse on a website  (Read 8964 times)

0 Members and 1 Guest are viewing this topic.

Offline Misuzu

  • Sr. Member
  • ****
  • Posts: 274
Avast found a Trojan Horse on a website
« on: April 25, 2010, 07:26:38 AM »
I'm not really concerned since Avast stopped it, MBAM (A up-to-date MBAM) quick scan found nothing and the BitDefender Quick Scan also didn't find anything. But do I report what websites the malware comes from here? I'm not to sure. Heh..  :P

Avast Warning Said:

File name: hxxp://google.analytics.com.sbpbjxiqsfix.info/kav/kav4.php
Malware name: JS:Prontexi-AP[Trj]
Malware type: Trojan Horse
VPS version: 100424-1, 04/24/2010

... I have gotten other warnings from Avast about a lot of malware from "kav" things... But anyway!

I added a attachment of a picture of the pop-up just in case I misspelled something, there's a lot of letters and numbers in there.


Thank you for reading.
Many apologizes if I wasn't supposed to post this.
« Last Edit: April 25, 2010, 07:34:52 AM by Misuzu »
|  Free Avast!   |  Malwarebytes Anti-Malware (Both up-to-date) |


Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #2 on: April 25, 2010, 03:02:10 PM »
The web shield blocked/stopped the download to your system because the only option is to abort the connection (dropping that item) so it won't have gotten on to your system.

This is masquerading as google.analytics.com to make you think that is where it is from when in fact it is from this domain sbpbjxiqsfix.info which avast has on its malicious sites list, see image.

Note, avast! 5.0 has been released for almost three months now, I would suggest you install that if you haven't got win9.x or winME.
« Last Edit: April 25, 2010, 03:04:39 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Avast found a Trojan Horse on a website
« Reply #3 on: April 25, 2010, 03:30:27 PM »
Hi Misuzu

This is what was found there. Last time suspicious software was found here was on 2010-04-24.
Malicious software includes 3 trojans, 2 exploits.

This site was hosted on 1 network(s) including AS21844 (THEPLANET).

Yes the site has been hosting malicious software to infect 3 domains, e.g.: idolator.com/, piratesonlineforums.com/, googlesyndication.com/,

http://scanner.novirusthanks.org/file/9106011b34c7180c8ff4891916e08c0f/a2F2NC5waHA=/
now seems given as clean

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Misuzu

  • Sr. Member
  • ****
  • Posts: 274
Re: Avast found a Trojan Horse on a website
« Reply #4 on: April 25, 2010, 03:53:47 PM »
Thanks for all your help!  ;D
I appreciate it!

I'm not very "malware-smart" but I'm learning more from researching and this forum. :)
Except for I don't know what ad poisoning is, but I think I can guess what it is. (Poisoning ads with malware?)

And yeah, I probably should update, I have Avast! 5.0 on my new computer and it works great.

Thanks again!
|  Free Avast!   |  Malwarebytes Anti-Malware (Both up-to-date) |

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #5 on: April 25, 2010, 04:36:46 PM »
<snip>
And yeah, I probably should update, I have Avast! 5.0 on my new computer and it works great.

Thanks again!

You're welcome.

Not only does it work great (for me also) and looks better, it provides better protection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Misuzu

  • Sr. Member
  • ****
  • Posts: 274
Re: Avast found a Trojan Horse on a website
« Reply #6 on: April 25, 2010, 08:05:42 PM »
Question about Avast! 5.0:

I just downloaded the .exe file for it from Avast's website. Am I supposed to uninstall Avast! 4.8?
Avast! 4.8's icon also had a "X" on it or something similar and Window Defender told me that changes was made to my computer when I was installing Avast! 5.0.

After Avast! 5.0 installed, Windows Defender said that Avast was out of date.

Are all these things normal when you install Avast! 5.0?

Should I uninstall Avast! 4.8? Will it cause any problems if I don't?
And how do you uninstall Avast! 4.8?

Sorry for all the questions. That should be my last question in this topic. Sorry for anything off-topic as well.
Thanks!
|  Free Avast!   |  Malwarebytes Anti-Malware (Both up-to-date) |

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #7 on: April 25, 2010, 09:03:20 PM »
You could have installed 5.0.507 (the latest version) over 4.8 as that would have retained your registration information, remover 4.8 and installed 5.0.

So if you just downloaded the installation file and installed it, avast 4.8 shouldn't be there.

I don't know anything about windows defender so I can't advise what to do about that, I do know it can be a pain in the rear though by stopping new startup items.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Misuzu

  • Sr. Member
  • ****
  • Posts: 274
Re: Avast found a Trojan Horse on a website
« Reply #8 on: April 25, 2010, 09:48:10 PM »
You could have installed 5.0.507 (the latest version) over 4.8 as that would have retained your registration information, remover 4.8 and installed 5.0.

So if you just downloaded the installation file and installed it, avast 4.8 shouldn't be there.

I don't know anything about windows defender so I can't advise what to do about that, I do know it can be a pain in the rear though by stopping new startup items.

Your right, I just checked and Avast 4.8 is gone now.

Thanks again.  :)
|  Free Avast!   |  Malwarebytes Anti-Malware (Both up-to-date) |

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #9 on: April 25, 2010, 11:10:52 PM »
No problem, glad I could help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

idontknow

  • Guest
Re: Avast found a Trojan Horse on a website
« Reply #10 on: April 27, 2010, 12:30:27 AM »
Hi !

I thank you all so much for having such a great product. I too had the warning screen from Avast last night, and was scared. I disconnected and immediately ran a full system scan. Nothing was detected.

Here's how mine showed up: hxxp://google.analytics.com.fhccvgjohscc.info/kav/KAV4.exe [L] JS:Prontexi-AP [Trj] (0)

I was on mediatakeout.com when it happened. Won't be going there again.

Thanks again for a great product.



« Last Edit: April 27, 2010, 09:46:12 PM by misak »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #11 on: April 27, 2010, 01:07:38 AM »
Yes another link trying to look like the official google analytics but not, just another no name malicious site, fhccvgjohscc.info.

Please 'modify' your post change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites, thanks.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

idontknow

  • Guest
Re: Avast found a Trojan Horse on a website
« Reply #12 on: May 11, 2010, 09:04:41 AM »
Sorry bout that. I'll remember next time.  :-[

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Avast found a Trojan Horse on a website
« Reply #13 on: May 11, 2010, 02:57:39 PM »
No problem.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security