Author Topic: Chrome Malware?  (Read 6843 times)

0 Members and 1 Guest are viewing this topic.

Offline a_vast

  • Sr. Member
  • ****
  • Posts: 233
Chrome Malware?
« on: April 18, 2015, 12:21:15 AM »
Hi,

When I go to Chrome I get this:



Checked out the numbers - google says it is an IP address in the Russian Federation :-o

What's going on please?

Thanks,

AV

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Chrome Malware?
« Reply #1 on: April 18, 2015, 12:24:49 AM »

Offline a_vast

  • Sr. Member
  • ****
  • Posts: 233
Re: Chrome Malware?
« Reply #2 on: April 18, 2015, 05:21:36 AM »
https://forum.avast.com/index.php?topic=53253.0

Thanks. If this is all the help Avast forum now offers I am out of here back to McAfee.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Chrome Malware?
« Reply #3 on: April 18, 2015, 12:30:09 PM »
It is just a start, we do offer more help.
But without knowing (relevant) details we can't do anything (much) for you.
Keep in mind that we can't see your system and what is going on.

You message doesn't make much sense.
You can't go to Chrome.
It is a browser.
You can download it, install it, use it, that is all.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Chrome Malware?
« Reply #4 on: April 18, 2015, 01:09:26 PM »
Hi a_vast,

The alert is to notice you you landed at a site that redirects you here: https://www.virustotal.com/en/domain/sb.adtidy.org/information/
via for example -adguardadblockerATadguard.com.xpi infested with JS/Redirector.BB through cybercriminal redirecting to malcode.

The logs that Eddy demanded are necessary for a qualified removal expert to remove this from the browser.
McAfee cannot help you either against this intentional evil persisitent redirection malcode.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Chrome Malware?
« Reply #5 on: April 18, 2015, 01:16:10 PM »
https://forum.avast.com/index.php?topic=53253.0

Thanks. If this is all the help Avast forum now offers I am out of here back to McAfee.

You do know, those instructions are standard across all reputable forums right?

GeekstoGo: http://www.geekstogo.com/forum/topic/2852-malware-and-spyware-cleaning-guide/
http://www.whatthetech.com/
http://www.malwareremoval.com/
http://www.spywarehammer.com/

I think you get my point. Standard UNITE logs they need to repair your System.

UNITE: http://uniteagainstmalware.com/
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Chrome Malware?
« Reply #6 on: April 18, 2015, 01:18:25 PM »
https://forum.avast.com/index.php?topic=53253.0

Thanks. If this is all the help Avast forum now offers I am out of here back to McAfee.

Yes, when McAfee continues to block it, let us know. We will still be here, waiting.(*Delay*).(*Delay*).(*Delay*).(*Delay*).(*Delay*).

This is all we have ever offered by the way. Take a quick scan through any case you want. Those instructions are always posted, and they almost always receive help, unless overlooked.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Chrome Malware?
« Reply #7 on: April 18, 2015, 02:22:11 PM »
I can see where the OP i coming from though, a post where someone on an Avast Forum tells us to download a whole slew of unfamiliar programs (except MWB, I like that one). It can seem like a lot at first glance, especially when he was maybe hoping that it was already known about and solved.

I just got this as well, the IP corresponds to an Andrey Korolev in the Russian Federation.

https://www.findip-address.com/185.22.60.101/whois

How do we know who the actual Avast employees are, to verify that Avast is actually recommending the install of those programs in the linked forum?

Offline a_vast

  • Sr. Member
  • ****
  • Posts: 233
Re: Chrome Malware?
« Reply #8 on: April 18, 2015, 06:19:32 PM »
Yes, you blew my gasket after I went to all the trouble to upload a screenshot plus homework on that url as well - only to be awarded with a link to 'overkill' for someone who is already anxious about what's going on with their computer I feel. We do need some human interaction here please, which has since surfaced :)

Probably have most of those scan programs, I wanted an initial reaction to that Avast pop-up, "don't know - go here - try this" would have been more acceptable.

For the record here's the boot scan summary - can't find the actual log - Avast please give us a user-friendly tab for logs.



Will go back to the Avast link with thanks.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Chrome Malware?
« Reply #9 on: April 18, 2015, 06:25:17 PM »
Just a guess...
You have AdGuard installed ?

Offline a_vast

  • Sr. Member
  • ****
  • Posts: 233
Re: Chrome Malware?
« Reply #10 on: April 18, 2015, 06:32:19 PM »
Just a guess...
You have AdGuard installed ?

Yes indeed - green shield with a check?

REDACTED

  • Guest
Re: Chrome Malware?
« Reply #11 on: April 18, 2015, 06:36:52 PM »
i had adguard installed but in Opera. got the same warning with same IP, after removing adguard, i havent got the warning yet

just check this https://www.who.is/dns/adguard.com
« Last Edit: April 18, 2015, 06:48:07 PM by muroko »

Offline a_vast

  • Sr. Member
  • ****
  • Posts: 233
Re: Chrome Malware?
« Reply #12 on: April 19, 2015, 01:11:08 AM »
That's weird - is there anything else reliable to replace adguard with please?

Thanks

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Chrome Malware?
« Reply #13 on: April 19, 2015, 02:46:49 AM »
I personally use uBlock... I find it mostly effective. No issues as of yet.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Chrome Malware?
« Reply #14 on: April 19, 2015, 03:02:47 AM »
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )