Author Topic: Help! Virus found: os _merge[3].js  (Read 2287 times)

Offline destro2k

  • Newbie
  • *
  • Posts: 8
    • Personal Message (Offline)
Help! Virus found: os _merge[3].js
« on: August 29, 2012, 12:35:35 AM »
Hello all,
I'm new to the forum. I just got my first virus hit. Is anyone familiar with virus os _merge[3].js? What does it do? I googled  it but found nothing.

Online Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17416
  • Gender: Male
    • Personal Message (Online)
Re: Help! Virus found: os _merge[3].js
« Reply #1 on: August 29, 2012, 05:41:13 AM »
we need more info here
what name did avast give it ?
where was it found?
what scan or shield found it?

you may attach a screen shot of the scan result
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline destro2k

  • Newbie
  • *
  • Posts: 8
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #2 on: August 29, 2012, 11:50:06 AM »
Virus Name: os _merge[3].js
Found in Temporary Internet Files folder.
Full system scan found virus.

I've attached screenshots of the Virus Chest & Scan Logs.

Offline destro2k

  • Newbie
  • *
  • Posts: 8
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #3 on: August 29, 2012, 12:25:44 PM »
It seems that my screenshot attachments aren't working so


Here is Virus Chest content:

Name                                              os_merge[3].js
Original location                              C:\Users\Destro2k\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\35A22CAC
Last changed                                  8/2/2012 9:19:51 PM
Transfer time                                   8/28/2012 9:16:43 AM
Virus                                                JS:Blacole-AV[Trj]



Here is the Scan Results content:

File name                                         C:\Users\Destro2k\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\35A22CAC\os_merge[3].js
Severity                                            High
Status                                              Threat: JS:Blacole-AV[Trj]
Action                                               Move to Chest
Result                                               Action successful

Offline flashgamer001

  • Jr. Member
  • **
  • Posts: 36
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #4 on: August 29, 2012, 02:56:27 PM »
Appears to be a malicious Javascript, possibly spreading a FakeAV trojan.

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22713
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #5 on: August 29, 2012, 03:20:13 PM »
There is a new zero day Java exploit for yet another unpatched vulnerability  http://www.geekstogo.com/
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html



Offline flashgamer001

  • Jr. Member
  • **
  • Posts: 36
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #6 on: August 29, 2012, 03:24:27 PM »
Erm... it's JavaScript. Anyway, unless anything suspicious is going on, you probably don't need to worry.

Online Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17416
  • Gender: Male
    • Personal Message (Online)
Re: Help! Virus found: os _merge[3].js
« Reply #7 on: August 29, 2012, 07:01:44 PM »
Erm... it's JavaScript. Anyway, unless anything suspicious is going on, you probably don't need to worry.
what is it you try to say ....since it is marked red?


http://en.wikipedia.org/wiki/Blackhole_exploit_kit
« Last Edit: August 29, 2012, 07:12:01 PM by Pondus »
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22713
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #8 on: August 29, 2012, 07:08:23 PM »
The script exploits a Java vulnerability



Online Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17416
  • Gender: Male
    • Personal Message (Online)
Re: Help! Virus found: os _merge[3].js
« Reply #9 on: August 29, 2012, 07:15:13 PM »
@destro2k

Quote
Virus Name: os _merge[3].js
Found in Temporary Internet Files folder.
not correct .... os _merge[3].js is the file name

this is the virus name that avast gave it. JS:Blacole-AV[Trj].   ;)
« Last Edit: August 29, 2012, 07:16:54 PM by Pondus »
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17216
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #10 on: August 29, 2012, 07:19:45 PM »
Pondus,

It is only to demonstrate that he apparently visited a website with a malicious jacascript link that infected him, because he was vulnerable to what was exploited through that script.
That could be via a redirect and indeed could be a java exploit.
Therefore  it is advised that users disable java for the time being until the existing 3 zero days have been patched or start to use NoScript inside the browser to be protected. In google chrome put this in the address bar: "chrome://plugins" (without "") - then all your active plugins are shown, now tag disbable at the java plugin and you are done... It is essential the eventual use of javascript is blocked until used and then some use a separate browser just for this purpose (sandboxed),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline flashgamer001

  • Jr. Member
  • **
  • Posts: 36
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #11 on: August 29, 2012, 08:35:11 PM »
The script exploits a Java vulnerability
Ah, okay. Thank you for clarifying, essexboy. I didn't realize you were referring to the function of it and just thought you had misread it. My apologies.

Offline destro2k

  • Newbie
  • *
  • Posts: 8
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #12 on: August 30, 2012, 12:30:00 AM »
Flashgamer001,
Erm... it's JavaScript. Anyway, unless anything suspicious is going on, you probably don't need to worry.
You sound as though there is no need to be concerned. Are JavaScript virus's inherently low risk?

Polonus,
I took your advice and disabled the java plugin. What kind of problems should I expect to encounter on different websites as a result of disabling java plugin?

To all,
Should I wipe my system and reinstall OS?

Offline mchain

  • avast! Evangelist
  • Super Poster
  • ***
  • Posts: 1361
  • Gender: Male
  • Spartan Warriors
    • Personal Message (Offline)
Re: Help! Virus found: os _merge[3].js
« Reply #13 on: August 30, 2012, 07:46:21 AM »
hi destro2k,
Flashgamer001,
Erm... it's JavaScript. Anyway, unless anything suspicious is going on, you probably don't need to worry.
You sound as though there is no need to be concerned. Are JavaScript virus's inherently low risk?

Polonus,
I took your advice and disabled the java plugin. What kind of problems should I expect to encounter on different websites as a result of disabling java plugin?

To all,
Should I wipe my system and reinstall OS?
1.)  No to low risk, it's actually the other way around.
2.)  (Answering for Polonus. Hope you do not mind)  A website with a BlackHole exploit cannot affect you if java or flash is disabled.  You will not be able to view java content within your browser while it is disabled.  As the vendor, Sun Oracle, rarely issues out-of-band patches for java, you may have to wait for the next scheduled patch in October.
3.)  Go here and run these three programs:  Malwarebytes, OTL, and aswMBR.exe.  Scan logs will be produced and attach all logs here in your next reply.  Here:  http://forum.avast.com/index.php?topic=53253.0  A volunteer malware expert will be along to assist you shortly.

BTW, since Oracle seemingly will not give out-of-cycle patches, I do not run or have java on my system.  One less thing to worry about.
XP Pro SP3 P4 3.2 HT 2GB RAM AIS v 8.0.1489 Secunia PSI version 2.0.0.3003 TREND Micro RUBotted Beta Javacool SpywareBlaster version 5.0 Sandboxie v. 3.76 WOT (Web Of Trust) Browser reputation-based add-on http://www.mywot.com/

Online Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17416
  • Gender: Male
    • Personal Message (Online)
Re: Help! Virus found: os _merge[3].js
« Reply #14 on: August 30, 2012, 08:14:36 AM »
Quote
Should I wipe my system and reinstall OS?
why ? ..... avast found it and removed it
if you are suspicious follow suggestion 3 from  mchain and attach the logs requested
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.