Author Topic: Maybe malware site  (Read 4953 times)

0 Members and 1 Guest are viewing this topic.

Offline boombastik

  • Full Member
  • ***
  • Posts: 111
Maybe malware site
« on: September 09, 2011, 09:55:15 AM »
I think that i found a malware site with froud downloads.
hxxp://www.uptodown.com/

and from there---> hxxp://avast-home.uptodown.com
Is this site legitame?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Maybe malware site
« Reply #1 on: September 09, 2011, 12:14:26 PM »
URLVoid

Report   2011-09-07 21:27:58 (GMT 1)
Website   uptodown.com
Domain Hash   76b59d0c53fb780e3984234bcf529194
IP Address   46.105.108.62 [SCAN]
IP Hostname   ns222339.ovh.net
IP Country    -- (--)
AS Number   16276
AS Name   OVH OVH Systems
Detections   2 / 23 (9 %)
Status   SUSPICIOUS

Scanning site with:   hpHosts     DETECTED
Scanning site with:   ParetoLogic URL Clearing House     DETECTED



URLVoid

Report   2011-03-07 01:53:18 (GMT 1)
Website   avast-home.uptodown.com
Domain Hash   0113e3996e92a1cb1c02eee4b9baa414
IP Address   81.19.96.183 [SCAN]
IP Hostname   eva0600016-vip-media-ingea.eu.verio.net
IP Country    ES (Spain)
AS Number   2914
AS Name   NTT-COMMUNICATIONS-2914 - NTT America, Inc.
Detections   0 / 18 (0 %)
Status   CLEAN

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Maybe malware site
« Reply #2 on: September 09, 2011, 04:29:45 PM »
Hi boombastik & Pondus

Well the average scanners do not flag anything but javascript irregularity is being flagged,
maybe that was the reason for the suspicious status, see description below...

So scans lLook fine here: http://urlquery.net/report.php?id=2721
also here: http://siteinspector.comodo.com/public/reports/323138

But a specific JS unpacker scanner flags "maxruntime exceeded",
so 2 suspicious instances found, e.g.:
-www.uptodown.com/ suspicious
[suspicious:2] (ipaddr:46.105.108.62) (var portal) -www.uptodown.com/
here >     status: (referer=-gstatic.uptodown.net/js/es.v10.23.js)saved 50570 bytes f7332d72c7ec545b171964b79e133bc73fd0c20f
     info: [script] -partner dot googleadservices dot com/gampad/service.js

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Maybe malware site
« Reply #3 on: September 09, 2011, 04:49:30 PM »
Anyone remember avastfrance.fr or something like that which would download a Hoax/avast?
Maybe something alternative?
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline boombastik

  • Full Member
  • ***
  • Posts: 111
Re: Maybe malware site
« Reply #4 on: September 10, 2011, 06:53:11 AM »
Well i check some downlods from the site in a test machine with deep freeze.
All the downloads are legitame programmes  witch come with an installer  with a conduit toolbar.
(name:uptodown toolbar)
In the installer u have the option to install or not this crap with the option to change your home page in somthing like google powered by uptodown.
If it ur choise to install the toolbar without the search engine, it will change it. So the option to change your homepage simply dosent work.(it will change it with or without you confirmation).
Also the unistaller dont remove the toolbar.(if u want to remove it ,it comes with an unistaller but it doesnt work).So u need third party tools to remove it from IE.
Also i check the avast from their site, is it legitame to have the avast with the option of the toolbar?
An non experience user will install the avast with that toolbar but the real installer of avast has no toolbar..

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: Maybe malware site
« Reply #5 on: September 10, 2011, 07:27:55 AM »
An non experience user will install the avast with that toolbar but the real installer of avast has no toolbar..
In Internet Explorer WebRep is a toolbar. So the real avast installer does have a toolbar which is WebRep in IE  :P
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

Offline boombastik

  • Full Member
  • ***
  • Posts: 111
Re: Maybe malware site
« Reply #6 on: September 10, 2011, 07:34:15 AM »

All the downloads are legitame programmes  witch come with an installer  with a conduit toolbar.
(name:uptodown toolbar)

Well the diference is that u can unistall the webrep if u dont like it. For conduit can we say the same?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Maybe malware site
« Reply #7 on: September 11, 2011, 04:11:06 PM »
Hi boombastik,

Normally it should be like that via "Start", "Control Panel", "Uninstall a programme", Select "Conduit" and click uninstall, Click "Remove Conduit Engine and all your apps" button, click "Remove" button and you done, Conduit extension in Fx can be removed like other extensions, but sometimes help from a qualified remover is necessary to remove remnants/garbage. There are specific removal tools to do this,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!