Author Topic: yahoo inbox..trojan horse  (Read 11944 times)

0 Members and 1 Guest are viewing this topic.

buffy_92

  • Guest
yahoo inbox..trojan horse
« on: June 07, 2013, 11:53:20 AM »
hi everyone.
recently i receveid an email from yahoo, i don't  remember how sounds like, i deleted it, because i wasn't interested.(i didn't open it).
and after that avast reported me this:

URL:   http://optimized-by.rubiconproject.com/a...
Process:   C:\Program Files\Mozilla Firefox\firefox...
Infection:   HTML:Iframe-AMG [Trj]

And now...is still show me that pop out with it, when i;m tryin to acces yahoo mail.
Nothing at scan search, no suspicious procesess..
What can i do for that pop out? it;s getting me nervous.. :-\

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: yahoo inbox..trojan horse
« Reply #1 on: June 07, 2013, 11:54:39 AM »
follow guide and attach logs.   http://forum.avast.com/index.php?topic=53253.0


buffy_92

  • Guest
Re: yahoo inbox..trojan horse
« Reply #2 on: June 07, 2013, 12:04:12 PM »
no ofense, but i don't use mbam and otl.(last time when i used it i had some problems).
« Last Edit: June 07, 2013, 12:18:30 PM by buffy_92 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: yahoo inbox..trojan horse
« Reply #3 on: June 07, 2013, 12:24:44 PM »
Hi buffy_92,

Read this: http://www.securelist.com/en/descriptions/7101543/Trojan-Clicker.HTML.IFrame.amg
and see whether your host file has been tampered with trojan clicker
Use system restore to get your computer to an earlier clean state:
http://www.precisesecurity.com/tools-resources/troubleshooting/restore-windows-vista-or-windows-7-to-an-earlier-date/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

buffy_92

  • Guest
Re: yahoo inbox..trojan horse
« Reply #4 on: June 07, 2013, 12:28:26 PM »
ok thanks  :D

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: yahoo inbox..trojan horse
« Reply #5 on: June 07, 2013, 01:03:51 PM »
OTL is the most important log to see what the problem is.....if in your computer

your AdwCleaner log say search.....you have to run it and click the delete button to remove all the crap files lised
« Last Edit: June 07, 2013, 01:05:31 PM by Pondus »

kizayoma

  • Guest
Re: yahoo inbox..trojan horse
« Reply #6 on: June 07, 2013, 01:49:39 PM »
i have the same problem, it starts 2 hours ago. in opera and chrome. i think its a false positive, because avast is blocking some yahoo commercial pop up.
"The connection to optimized-by.rubiconproject.com was interrupted."
somebody from avast here to check it?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: yahoo inbox..trojan horse
« Reply #7 on: June 07, 2013, 01:53:18 PM »
https://www.virustotal.com/en/url/e21206f763993b027759195f931344638deb4187b7d2b79c0cd5c0c3494284cc/analysis/1370605909/

That's a site Analysis of http://optimized-by.rubiconproject.com/. Seems to be nothing wrong with it. I'll check the school proxy see if it blocks it. (It'll block just about anything malicious).

Edit: http://optimized-by.rubiconproject.com/  Seems to be down. Either it was infected and is now being cleaned, or the redirect never worked

And No I am not an Avast Staff member. A regular user online from the last 5 ish days.

1 more edit; I'm looking further into the report, at some point in time it was hosting a virus or worm and the Verdict was indeed Malicous. But the scanners lined up for this didn't detect anything.
« Last Edit: June 07, 2013, 01:58:27 PM by alan1998 »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Doebi

  • Guest
Re: yahoo inbox..trojan horse
« Reply #8 on: June 07, 2013, 02:09:20 PM »
This alert is also hitting on ANY quickmeme page. I'd be really interested to know if someone of these sites have been compromised or if this a string of similar false positives.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: yahoo inbox..trojan horse
« Reply #9 on: June 07, 2013, 02:12:32 PM »
WHat is a quick meme page? If you can give me a URL to it I can run it through Virus Total and see what it says. A recent version of Avast did detect a Trojan in Facebook which was a FP. Could be the same case. But if you want it check I need URL's to scan.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: yahoo inbox..trojan horse
« Reply #10 on: June 07, 2013, 02:18:25 PM »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

kizayoma

  • Guest
Re: yahoo inbox..trojan horse
« Reply #11 on: June 07, 2013, 03:06:41 PM »
please look attached file

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: yahoo inbox..trojan horse
« Reply #12 on: June 07, 2013, 03:11:38 PM »
What is the full link? I'll scan it.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

kizayoma

  • Guest

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: yahoo inbox..trojan horse
« Reply #14 on: June 07, 2013, 03:54:24 PM »
https://www.virustotal.com/en/url/19b2593e66ff011e32556a042ecb87893c669bbe98d42f6ceb55083e804190a5/analysis/1370613160/

Deemed clean. However at some point in time Bitdefender deemed it Malicous for Badware (Ransomware, Torjans etc) It lookeds to be clean right now though.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.