Author Topic: SAS Forum infected/underattack ?????  (Read 11157 times)

0 Members and 1 Guest are viewing this topic.

iroc9555

  • Guest
SAS Forum infected/underattack ?????
« on: November 03, 2012, 04:34:51 AM »
I tried to go to SAS forum after Avast! detected in my IE 8 Favorite SAS forum link as INI:shortcut-inf[trj]

WOW what a surprise 1 Web Shield detection and 13 Network Shield detections. Too many to attach screenshoot of alerts so here is the Avast! report:

Web Shield:
02/11/2012 20:47:56     -http://forums.superantispyware.com/|>{gzip} [L] HTML:Script-inf (0)

Network Shield:
02/11/2012 20:47:56     -http://forums.superantispyware.com/ [L] URL:Mal (0)
02/11/2012 20:47:56  -http://forums.superantispyware.com/public/style_images/master/advanced_search.png [L] URL:Mal (0)
02/11/2012 20:47:56    -http://forums.superantispyware.com/images/forum-top.png [L] URL:Mal (0)
02/11/2012 20:47:56    -http://forums.superantispyware.com/public/style_images/master/icon_quicknav.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/branding_bg.png [L] URL:Mal (0)
02/11/2012 20:47:57 -http://forums.superantispyware.com/public/style_images/master/profile/default_large.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/f_icon.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/maintitle.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/uploads/profile/photo-thumb-20915.jpg [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/uploads/av-10620.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/cat_minimize.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/top.png [L] URL:Mal (0)
02/11/2012 20:47:57    -http://forums.superantispyware.com/public/style_images/master/feed.png [L] URL:Mal (0)


Afterward my start page did not want to start up. I had Internet but when IE 8 and FF 16.0.2 were applied I got "Page not found". I ran MBAM and did not find anything so I tried again and this time my browsers started with my start page.

I did run all the programs requested. Besides AdwCleaner which found some old IE 7 app to edit DHTML, the rest I believe are clean. However I will appreciate if any of you gent would take a look at them just in case.

I think Avast! just save my skin. Thank avast!  ;D
« Last Edit: November 03, 2012, 04:47:05 AM by iroc9555 »

iroc9555

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #1 on: November 03, 2012, 04:40:42 AM »
Here are my 2 OTL logs.

true indian

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #2 on: November 03, 2012, 05:04:48 AM »
You are not alone!! even I am having URL MAL on SAS forum  ;D

Offline Geoffo

  • Jr. Member
  • **
  • Posts: 70
Re: SAS Forum infected/underattack ?????
« Reply #3 on: November 03, 2012, 09:47:22 AM »
Me too, my scan moved c\:users/favourites/superantispyware.com.indexpage.url to the virus chest. Name of file infected said was INI shortcut-inf[trj]. What's going on? Also my scan hangs at 58% for ages and then all of a sudden whizzes up to 99%, it hasn't done that before?
Win7, Chrome, Avast MBAM, SUS,

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: SAS Forum infected/underattack ?????
« Reply #4 on: November 03, 2012, 10:02:31 AM »
it sounds like the forum of sas might have been hijacked.

http://forum.avast.com/index.php?topic=47096.0
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline Geoffo

  • Jr. Member
  • **
  • Posts: 70
Re: SAS Forum infected/underattack ?????
« Reply #5 on: November 03, 2012, 10:17:27 AM »
it sounds like the forum of sas might have been hijacked.

http://forum.avast.com/index.php?topic=47096.0

Pretty useless link that, no mention of the SAS forum being hijacked - and it's a 2009 topic!!
Win7, Chrome, Avast MBAM, SUS,

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5600
  • Spartan Warrior
Re: SAS Forum infected/underattack ?????
« Reply #6 on: November 03, 2012, 11:52:16 AM »
Here, in avast! Free/Pro/Suite:  http://forum.avast.com/index.php?topic=108477.0
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: SAS Forum infected/underattack ?????
« Reply #7 on: November 03, 2012, 01:40:51 PM »
I would suggest a search of the Wilders forums as that is where these things normally get discussed when it isn't possible to discus them on the SAS forum if your AV is blocking it.

However, this is a bit strange in that it is only an issue at the forums. sub-domain as it is possible to visit    hXXp://www.superantispyware.com/ without an alert.

The multiple alerts isn't so much of an issue as essentially it is only the one alert on the forum.superantispyware.com sub-domain, so each connection to an image in that sub-domain would also trigger an alert.

My main interest is the very first alert you listed.
Quote from: mchain
Web Shield:
02/11/2012 20:47:56     -http://forums.superantispyware.com/|>{gzip} [L] HTML:Script-inf (0)

As that page appears to be loading a compressed script file - the |>{gzip} bit at the end as the HTML:Script-inf is a script injection alert.

The problem is once you get sufficient avast users getting a web shield alert on a site, that (through the avast! community) will eventually lead to the inclusion in the network shields malicious sites list. So this particular alert needs investigation as I suspect once that is resolved the network shield alerts would also be resolved.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

iroc9555

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #8 on: November 03, 2012, 02:08:36 PM »
The multiple alerts isn't so much of an issue as essentially it is only the one alert on the forum.superantispyware.com sub-domain, so each connection to an image in that sub-domain would also trigger an alert.

My main interest is the very first alert you listed.
Quote from: mchain
Web Shield:
02/11/2012 20:47:56     -http://forums.superantispyware.com/|>{gzip} [L] HTML:Script-inf (0)

As that page appears to be loading a compressed script file - the |>{gzip} bit at the end as the HTML:Script-inf is a script injection alert.


I agree with you DavidR that detection is the main concern.

Since Piriform forum was also detected as infected in an earlier topic yesterday I am taken no risks. I am pretty sure my logs are clean but I am waiting for Essexboy to take a look at my OTL logs.

Thank you.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SAS Forum infected/underattack ?????
« Reply #9 on: November 03, 2012, 03:27:13 PM »
Looks clean young sir... Any problems ?

iroc9555

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #10 on: November 03, 2012, 03:35:21 PM »
Thanks Essexboy.

No, no problems right now. Thanks again, and thanks for the young sir ;D too.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SAS Forum infected/underattack ?????
« Reply #11 on: November 03, 2012, 03:39:58 PM »
Run OTL and hit the cleanup button to remove the tools you have used  ;D

iroc9555

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #12 on: November 03, 2012, 03:44:09 PM »
Run OTL and hit the cleanup button to remove the tools you have used  ;D

Yes sir. I was waiting for your "all good specialist clean up his tools after everything is done" speech.  ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SAS Forum infected/underattack ?????
« Reply #13 on: November 03, 2012, 04:16:29 PM »
Do you want the whole 9 yards  ;D ;D ;D

iroc9555

  • Guest
Re: SAS Forum infected/underattack ?????
« Reply #14 on: November 03, 2012, 04:18:56 PM »
Do you want the whole 9 yards  ;D ;D ;D

 ;D  ;D  ;D