Author Topic: HTML:RedirME-inf [Trj] Detection  (Read 6658 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
HTML:RedirME-inf [Trj] Detection
« on: May 29, 2017, 01:16:27 AM »
Hello everyone,

After quite some search around here in the forum about this Trojan infection, I didn't fully found any situation quite like mine, or at least from my understanding or point of view of the problem.

This past week, when acessing the website "Feed2All" a pop-up from Avast appeared about 6/7 times a day for a whole week. Since than I've been unable to access the site. From what I've read, this happens for the fact of being block by Avast, correct? After this I checked the webiste on "VirusTotal" and everything seemed to look ok.

I've also downloaded Malwarebytes and ran it, and it only found "pup.optional.opencandy", which I believe might not be connected to this trojan problem, right?

So, after this I went to check my "Quarentine" on Avast, and a variety of ".exe" files are locked there, spotted on folders on my computer on which I've never seen or putted them there before, so my question is: are this files connected to the "Trojan" file?

Here they are:
Code: [Select]
http://i146.photobucket.com/albums/r274/kitsoyomo/PRINT.png
I must say I was pretty scared when finding reading about this Trojan, and finding out that this might be some kind of "malaware" from which someone has remote access to my computer, files, documents, etc.

I apologize in advance for my deep newbiness but this is just a scary situation since my computor is my work day tool!

Best regards,
Tiago

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: HTML:RedirME-inf [Trj] Detection
« Reply #1 on: May 29, 2017, 01:27:06 AM »
Sucuri  >>  https://sitecheck.sucuri.net/results/myfeed2all.eu

Quote
  After this I checked the webiste on "VirusTotal" and everything seemed to look ok.   
Virustotal URL scan is a blacklist check, it does not scan for website malware

« Last Edit: May 29, 2017, 01:34:40 AM by Pondus »

REDACTED

  • Guest
Re: HTML:RedirME-inf [Trj] Detection
« Reply #2 on: May 29, 2017, 01:44:08 AM »
Thanks for the info! I was really clueless on this one.

So, does that mean that I might have been infected and some ".exe" files were installed and someone had acess to my documents and information?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: HTML:RedirME-inf [Trj] Detection
« Reply #3 on: May 29, 2017, 02:01:44 AM »

REDACTED

  • Guest
Re: HTML:RedirME-inf [Trj] Detection
« Reply #4 on: May 29, 2017, 02:08:37 AM »
Cool. So, this ".exe" files might not have nothing to do with this problem?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: HTML:RedirME-inf [Trj] Detection
« Reply #5 on: May 29, 2017, 02:16:22 AM »
Impossible to say as we can't see all the info given in avast quarantine


REDACTED

  • Guest
Re: HTML:RedirME-inf [Trj] Detection
« Reply #6 on: May 30, 2017, 03:05:56 PM »
Hi,

I am getting this same Trojan popup, it pops up when I start to browse in Firefox, and only appears once per session. (I no longer visit feed2all, but it still pops up)

I ran MB with  rootkits enabled and Farbar and the text files are attached.

Since Avast is blocking it, I'm not sure this Trojan is causing any harm, but I would like to remove it. I have also run several other rootkit programs, but none of them find any malware. Should I uninstall Firefox?

Thank you.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: HTML:RedirME-inf [Trj] Detection
« Reply #7 on: May 30, 2017, 03:40:11 PM »
@lundjro Have you tried cleaning your browser(s) with AdwCleaner ?

AdwCleaner  >>  https://www.malwarebytes.com/adwcleaner/

OBS: When asking for help, always start your own topic. Helping multiple users in same topic create chaos





REDACTED

  • Guest
Re: HTML:RedirME-inf [Trj] Detection
« Reply #8 on: May 30, 2017, 09:41:03 PM »
@lundjro Have you tried cleaning your browser(s) with AdwCleaner ?

AdwCleaner  >>  https://www.malwarebytes.com/adwcleaner/

OBS: When asking for help, always start your own topic. Helping multiple users in same topic create chaos

Sorry, next time I will start a new topic.

Thank you for the quick reply! adwcleaner found and removed the threat below.

[-] File deleted: C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\0htyjw4k.default\invalidprefs.js