Author Topic: web site 2baksa.net avoid  (Read 6735 times)

0 Members and 1 Guest are viewing this topic.

vbfg456

  • Guest
web site 2baksa.net avoid
« on: August 20, 2012, 03:35:08 AM »
There is a java program that is downloaded when you access this site.
It appears this program will remove chrome update and any use of keyboard will lock your system, after you reboot.


Theo Peterbroers

  • Guest
Re: web site 2baksa.net avoid
« Reply #1 on: August 20, 2012, 06:17:53 AM »
Hi vbfg456,

Thanks for warning us off this warez site.

I'm no malware removal expert, but I have four questions for you
- does your system still get locked,
- did you get any message when your system locks,
- does your system show a bootmenu offering you to start a recovery console,
- does your system lock when you start in safe mode? You can get into safe mode by repeatedly pressing F8 key during boot.

Best regards,


Theo Peterbroers

  • Guest
Re: web site 2baksa.net avoid
« Reply #3 on: August 20, 2012, 10:49:00 AM »
Quttera:
Normalized URL:    2baksa.net
Submission date:    Mon Aug 20 05:49:45 2012
Server IP address:    178.218.212.214
Country:    Russian Federation
Malicious files:    0
Suspicious files:    0
Potentially Suspicious files:    2
Clean files:    160

Potentially Suspicious files: 2
/all-include.js
File size[byte]:   
224339
Threat type:   
Potentially Suspicious
Details:   
Detected hidden reference to external web resource.
Reason:   
Detected generation of hidden DOM element [iframe].
MD5:   
1DFFE292D407F3F5587F99CC65166457
Scan duration[sec]:   
0.547000
/billingXX.maxhost.ru/order/host.php?name=nowa
File size[byte]:   
67
Threat type:   
Potentially Suspicious
Details:   
Detected unconditional redirection to external web resource.
Reason:   
<meta http-equiv="refresh" content="0; url=hXXp://www.maxhost.ru/">
MD5:   
1379511935659EB5BFBA206CFBF51BB0
Scan duration[sec]:   
0.005000

Dunno, still learning. When I open it now, I see a site that clearly proclaims Torrent Treker. But I swear that when I first opened it this morning, it had an altogether different design and proclaimed Warez. Hmmm, probably was not yet fully awake and clicked on wrong link.

Best regards,
« Last Edit: August 20, 2012, 11:07:40 AM by Kwartet! »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: web site 2baksa.net avoid
« Reply #4 on: August 20, 2012, 03:05:00 PM »
Norman lab say there is a redirect

2baksa.net.htm - Redir.ID

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: web site 2baksa.net avoid
« Reply #5 on: August 20, 2012, 03:26:49 PM »
This is also here: teasertop.ru/js/teasertop.js considered as suspicious
Probably worth blocking, see: http://adzilla.fanboy.co.nz/forums/viewtopic.php?t=10319&p=28476
and where it was adopted: http://hg.fanboy.co.nz/rev/404fd502d6e0
avast webrep also alerts the link to ru.redtram dot com a spammer
Помойка. Фейковые новости    " listed  here: http://firefox.org.ua/xpi/adblock_ua.txt

polonus
« Last Edit: August 20, 2012, 03:33:07 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

vbfg456

  • Guest
Re: web site 2baksa.net avoid
« Reply #6 on: August 21, 2012, 12:47:58 AM »
i found out why the keyboard stopped working. it turns out the kvm switch, does not work on the computer that i use for the internet.
the other computers do not have any problems. not a problem with the cable.

i toke several tries to uninstall and put chrome back on. would say can not uninstall because some files are missing.
i toke getting the full version (20mg) to install from that. then i was able to uninstall and reinstall, so it is back to normal.

do not know why the update files were missing. they were listed in the startup program list. (just file missing).


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: web site 2baksa.net avoid
« Reply #7 on: August 21, 2012, 12:51:25 AM »
Hi vbfg456,

Good to hear these issues have been solved. Welcome to these forums here,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!