Author Topic: Help  (Read 20167 times)

0 Members and 1 Guest are viewing this topic.

inthefrey

  • Guest
Re: Help
« Reply #15 on: June 15, 2010, 05:38:32 AM »
Just to bump this thread, my AVAST started flagging this same url about a week ago.

Phobos

  • Guest
Re: Help for media9s.com
« Reply #16 on: June 15, 2010, 12:27:34 PM »
"bump" (+ subject titled)

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Help
« Reply #17 on: June 15, 2010, 01:31:21 PM »
Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Maybe you could contact its webmaster.
The best things in life are free.

Phobos

  • Guest
Re: Help for media9s.com
« Reply #18 on: June 15, 2010, 01:37:03 PM »
i concur with djDave

cleaned / checked > open Google (whereas he is opening Yahoo) >  let it sit a few minutes > warning comes up
« Last Edit: June 15, 2010, 01:39:26 PM by Phobos »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Help
« Reply #19 on: June 15, 2010, 01:41:06 PM »
i concur with djDave

cleaned / checked > open Google (whereas he is opening Yahoo) >  let it sit a few minutes > warning comes up
http://forum.avast.com/index.php?topic=60716.msg512868#msg512868
The best things in life are free.

Phobos

  • Guest
Re: Help
« Reply #20 on: June 15, 2010, 01:43:56 PM »
in other words, another thread on the subject:
http://forum.avast.com/index.php?topic=60716.msg512868#msg512868
« Last Edit: June 15, 2010, 01:57:53 PM by Phobos »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Help
« Reply #21 on: June 15, 2010, 01:51:36 PM »
Or run OTL, post the log`s as attachments, and let Essexboy have a look....
http://forum.avast.com/index.php?topic=53253.0

djDave

  • Guest
Re: Help
« Reply #22 on: June 15, 2010, 03:06:51 PM »
I had the same problem as others are having with:
media9s.com/cgi/crhwmrxg.php?gggg=6733616xxx
nopagency.com/cgi/kpudd.php?ddddd=6733616xxx
88.80.7.152/cgi/oejo.php?dsi=6733616xxx (no xs on the ends)
for about a week, I tried everything I had, full scans with Avast, Malwarebytes & SuperAntiSpyware and they did not find these. I turned off restore, dumped my temps. did a reboot, turned System Restore back on, updated Malwarebytes (always do this) and did a full scan (said clean), updated SuperAntiSpyware and it found these: (trojan.Dropper/Win-NVxxx(without the xs))
in that there were 2 -
(C:\WINDOWS\MSVIDEO.DLLxxx(without the xs))
I moved them to Quarantine yesterday and have not seen the blocked warning again ! I hope I'm done with them...I hope this helps someone...dave

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Help
« Reply #23 on: June 15, 2010, 04:54:12 PM »
Thanks for sharing.

You say you moved them to quarantine in SAS, it would be helpful if you can send a sample to avast.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.

Unfortunately that would need you to first restore them from SAS quarantine, copy to the avast chest and then run an SAS scan again to remove it again...
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
« Last Edit: June 15, 2010, 06:12:58 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

djDave

  • Guest
Re: Help
« Reply #25 on: June 16, 2010, 02:04:18 AM »
Hi DavidR, I hope the info from polonus is what you need, as I'm kinda chicken to move the problem back into my PC.. I do have logs from OTL that I saved while I had the problem, I could E_Mail them to you or to an Avast address of your choice if that would be of any help. Thanks again for all you and others do here..dave

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Help
« Reply #26 on: June 16, 2010, 02:34:16 AM »
Not really, my concern is sending a sample to avast as they didn't detect it, so that they can hopefully add it to the virus definitions. The logs don't provide the sample which would be used to create a detection signature.

I understand not wanting to restore it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Phobos

  • Guest
Re: Help
« Reply #27 on: June 16, 2010, 09:50:11 AM »
I had the same problem as others are having with:
media9s.com/cgi/crhwmrxg.php?gggg=6733616xxx
nopagency.com/cgi/kpudd.php?ddddd=6733616xxx
88.80.7.152/cgi/oejo.php?dsi=6733616xxx (no xs on the ends)
for about a week, I tried everything I had, full scans with Avast, Malwarebytes & SuperAntiSpyware and they did not find these. I turned off restore, dumped my temps. did a reboot, turned System Restore back on, updated Malwarebytes (always do this) and did a full scan (said clean), updated SuperAntiSpyware and it found these: (trojan.Dropper/Win-NVxxx(without the xs))
in that there were 2 -
(C:\WINDOWS\MSVIDEO.DLLxxx(without the xs))
I moved them to Quarantine yesterday and have not seen the blocked warning again ! I hope I'm done with them...I hope this helps someone...dave



Worked ... Thanks djDave!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Help
« Reply #28 on: June 16, 2010, 03:29:14 PM »
Before you did that, did you send a sample to avast as suggested earlier in Reply #23 before quarantining it ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

djDave

  • Guest
Re: Help
« Reply #29 on: June 16, 2010, 04:18:31 PM »
To David R, If someone else is working on this, could you explain how to find it in the PC, to send a sample to avast as SAS does not give much info about it once it's in SAS Quarantine ?

to: Phobos, I'm glad it worked for you, I forgot to say that after all seemed well again I went to System restore and created a new restore point.