Author Topic: Malware JS:Pdfka-DH [Expl]  (Read 16826 times)

0 Members and 1 Guest are viewing this topic.

Oxydose

  • Guest
Malware JS:Pdfka-DH [Expl]
« on: March 25, 2009, 03:15:41 AM »
Hello, I visited a wikianswer page and I got a warning that the page contained malware.  I aborted the connection, but went back to the page to check if it was just a goof.  So, my question is, if I aborted the connection, I'm safe?  I was still able to visit the page.

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Malware JS:Pdfka-DH [Expl]
« Reply #1 on: March 25, 2009, 04:46:00 AM »
Yes, you are safe. The webshield would have prevented the transfer of any detected malware on that page.
What was the page concerned? Please don't post the link as-is; sanitize it first by replacing the "TT" s in http with "X's.
Windows 10,Windows Firewall,Firefox w/Adblock.

Oxydose

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #2 on: March 25, 2009, 05:02:51 AM »
Alright, thanks.

Here's the link:  hxxp://wiki.answers.com/Q/Is_warhammer_fun
Do you want the link given in the on-access scanner as well?



Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Malware JS:Pdfka-DH [Expl]
« Reply #3 on: March 25, 2009, 05:11:16 AM »
Yes please.
Also, what version of Java do you use? http://java.com/en/download/dt_verify.jsp?plugin=true&latest=false&users_jre=1.6.0_11
I visited the site and got no warning.
Windows 10,Windows Firewall,Firefox w/Adblock.

Oxydose

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #4 on: March 25, 2009, 05:15:47 AM »
Hm, I haven't updated java in a while, maybe that's the issue?  Version 6 update 11.

last infected: hxxp://site1.wikianswers.com/templates/scripts/~abcdekjfghilsMrNO.js?v=42356\{gzip}

tenspound

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #5 on: March 25, 2009, 05:23:04 AM »
I clicked on wiki answers also and this biohazard symbol with a siren noise popped up and it said it was from avast.  I did the whole abort thing but i thought baout it after and was wondering if that is what show up when malware is trying to get in.  So if anyone knows for sure, please let me know. thanks josh.

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Malware JS:Pdfka-DH [Expl]
« Reply #6 on: March 25, 2009, 05:36:21 AM »
Josh, if you aborted the connection, you are safe. Yes, malware would have downloaded without the shield. (Whether it would have done any damage on an up to date system is another matter, and beyond my knowledge.)

Oxydose, I have the latest Java version also. Yours is a version prior to mine, but has no known vulnerabilities. (Update if you wish, but no urgency, I think.)

The reason I got no warning initially is that I use the Noscript addon. Suspending it produces the Avast alert.
I have contacted the site with the information about the exploit.

Just goes to show you (assuming this is not a false alarm, generally a safe assumption with webshield warnings): sites can be hacked. The web can be a hazardous place.
(And Avast rocks!)
Windows 10,Windows Firewall,Firefox w/Adblock.

Oxydose

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #7 on: March 25, 2009, 05:52:13 AM »
Indeed.  Thank you for the help!

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Malware JS:Pdfka-DH [Expl]
« Reply #8 on: March 25, 2009, 05:54:18 AM »
Welcome.  :D
Windows 10,Windows Firewall,Firefox w/Adblock.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89165
  • No support PMs thanks
Re: Malware JS:Pdfka-DH [Expl]
« Reply #9 on: March 25, 2009, 04:15:16 PM »
JAVA Version 6 update 13 is now the latest version.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

WikiAnswers

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #10 on: March 25, 2009, 04:44:10 PM »
Which definition file do you guys have? We have tried to reproduce this warning on wiki.answers.com, but all is well. (Yes, we turned off No Script.) We even turned on "show detailed scanning" and watched Web Shield scan that script, but it didn't complain. We're using VPS 090324-0.

Could it be that this was a problem in 090323-0, which was already corrected? There's another discussion (topic 43627) that reported the same exact warning on a completely different script. That discussion did cite 090323-0. Could you guys please update your definitions and see if the problem persists?


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89165
  • No support PMs thanks
Re: Malware JS:Pdfka-DH [Expl]
« Reply #11 on: March 25, 2009, 05:48:50 PM »
Well I'm using 090324-0 and using the url in reply #4 above I get an alert.

I have reported it as a possible false positive, so hopefully it should be quickly analysed as corrected as required.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89165
  • No support PMs thanks
Re: Malware JS:Pdfka-DH [Expl]
« Reply #12 on: March 25, 2009, 05:59:41 PM »
Update:

I captured the file when avast detected it and I uploaded it to virustotal, http://www.virustotal.com/analisis/a9c5a877257dc841530bf79a30a76137 for scanning and the results would suggest it is a false positive detection with only 2 of 40 scanners finding anything.

GData is the other scanner and since that also uses avast as one of its two scanners it is effectively only one detection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

WikiAnswers

  • Guest
Re: Malware JS:Pdfka-DH [Expl]
« Reply #13 on: March 26, 2009, 10:11:45 AM »
Thanks a lot for the update, DavidR, as well as the validation. Indeed, a couple of our users have reported that the problem resolved itself, presumably via a definition file update.

Unfortunately, Avast's own customer support has yet to even acknowledge the urgent ticket I opened yesterday. Is that par? Any idea how long it usually takes them to follow up? Obviously, I'm pleased they seem to have fixed it. But I'd still like to know what happened, and how it can be prevented in the future.

Thanx again.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11855
    • AVAST Software
Re: Malware JS:Pdfka-DH [Expl]
« Reply #14 on: March 26, 2009, 10:31:15 AM »
I kind of doubt you'll get any reasonable response - as there is none.
False positives happen, that's an unfortunate fact... and we try to fix them as soon as possible. There's nothing more to say, I'm afraid.