Author Topic: HTML:iframe-inf infection (logs added)  (Read 3413 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
HTML:iframe-inf infection (logs added)
« on: January 29, 2018, 02:23:18 AM »
Hello all,

I have a problem similar to one discussed two years ago (https://forum.avast.com/index.php?topic=165280.0). In my case though it’s not the navigator that’s being attacked, but my torrent client (qBittorrent). Update: Chrome was induced to spontaneously open a suspect URL too, but only once

Actually, I think the infection took place through a website and now it’s trying to process something through my torrent client.

Anyway, Avast notices HTML:iframe-inf infection when qBittorrent is running, but cannot find any threat while scanning.

MBAM’s scan identified nothing either. However, as it’s now installed, it took the place of Avast in notifying me something is wrong when I run qBittorrent (I added a log generated by it too).

Neither FRST.

ASWMBR did found something. While it is scanning, even in safe mode without internet connection, it shows:
Service ESProtectionDriver C:\WINDOWS\system32\drivers\mbae64.sys **LOCKED**
after some seconds, Windows shows a blue screen. It says that aswmbr.sys has failed.

Could someone please help me?
Thank you in advance
« Last Edit: January 29, 2018, 04:57:48 PM by borisansky »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: HTML:iframe-inf infection (logs added)
« Reply #1 on: January 29, 2018, 07:05:33 AM »
Quote
  Anyway, Avast notices HTML:iframe-inf infection when qBittorrent is running, but cannot find any threat in its scanning
Because infection is located on the URL that your torrent program is connecting to

What does the avast message say (all info) you may post a screenshot


REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #2 on: January 29, 2018, 12:29:32 PM »
Quote
  Anyway, Avast notices HTML:iframe-inf infection when qBittorrent is running, but cannot find any threat in its scanning
Because infection is located on the URL that your torrent program is connecting to

What does the avast message say (all info) you may post a screenshot

Asked screenshot is attached.

Avast blocked yesterday an attempt of connecting to a URL not through qBittorrent, but through Chrome. Unfortunately I didn’t a screenshot at the moment.


REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #4 on: January 29, 2018, 04:18:23 PM »
Well, file check detected a Trojan, so It is not a false positive, right?

Is there something I can do? I’m not trying to access these URLs, something in my computer is generating a command to do it

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: HTML:iframe-inf infection (logs added)
« Reply #5 on: January 29, 2018, 04:22:53 PM »
Quote
   something in my computer is generating a command to do it
As your screenshot say ... your torrent program

Risk info  >>  http://www.informationsecuritybuzz.com/articles/torrenting-know-risks-take/

« Last Edit: January 29, 2018, 04:25:54 PM by Pondus »

REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #6 on: January 29, 2018, 04:26:14 PM »
I think this is not the case. As I’ve already said, Chrome was induced to it too

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: HTML:iframe-inf infection (logs added)
« Reply #7 on: January 29, 2018, 04:32:17 PM »
I think this is not the case. As I’ve already said, Chrome was induced to it too
Same URL?
Same detection?


REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #8 on: January 29, 2018, 04:34:29 PM »
Same detection (HTML:iframe-inf) but on another URL, which I didn’t take note

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: HTML:iframe-inf infection (logs added)
« Reply #9 on: January 29, 2018, 04:40:45 PM »
Malware expert is notified and will check your attached logs. It may take hours before he is online


Iframe info  >>  https://www.theguardian.com/technology/2008/apr/03/security.google
Iframe info  >>  https://en.m.wikipedia.org/wiki/Iframe_virus

« Last Edit: January 29, 2018, 04:46:14 PM by Pondus »

REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #10 on: January 29, 2018, 04:45:38 PM »
Thank you

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: HTML:iframe-inf infection (logs added)
« Reply #11 on: January 29, 2018, 09:08:06 PM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: type C:\IORRT\IORRT.bat
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Re: HTML:iframe-inf infection (logs added)
« Reply #12 on: January 29, 2018, 09:28:57 PM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: type C:\IORRT\IORRT.bat
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Thank you, it did work! I put qBittorrent to run and it's working fine

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: HTML:iframe-inf infection (logs added)
« Reply #13 on: January 29, 2018, 10:42:47 PM »
I didn't do anything. I only checked file that turns to be MS Office activator. In qBittorrent, find in trackers blocked URL and remove it from tracker list.


The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.
Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.