Author Topic: VBS:Malware-gen  (Read 201264 times)

0 Members and 1 Guest are viewing this topic.

7thachmad

  • Guest
Re: VBS:Malware-gen
« Reply #180 on: October 29, 2008, 03:47:06 AM »
i've got problems with irritating malware and trojan called win32:Pink [trj] and vbs:malware-gen AVASt home edition won't work even the splash screen scanner but the service is still running, looks like if there is opened windows that contain text antivirus the trojan quickly disabled it.

i've used boot time scan and turn off the system restore it successfully delete Autorun.inf at the c:\ and d:\ drive and i've forced to delete netcfg.dll and netcfg.0000 at system32\com folder that recognize as win32: pink[trj] but it keep coming when the system start again

please help  :'(

i use windows xp service pack 2 build 2600, VPS i forgot.

redsock2

  • Guest
Re: VBS:Malware-gen
« Reply #181 on: November 03, 2008, 06:56:06 AM »
Hello,

I have a VBS:Malware-gen

when I access
http://www.equilibriarte.org

VPS-Version: 081102-0, 11/02/2008

I think they use Iframes - Is there really a Problem with this site??
Please take a look...
Thanks for your help !!!

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #182 on: November 03, 2008, 07:57:56 AM »
Yep, they're serving something long, strange and encrypted at the end of the html.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: VBS:Malware-gen
« Reply #183 on: November 03, 2008, 02:10:00 PM »
redsock2, nowadays, avast website detection is more accurate and higher than other antivirus. Welcome to avast forums.
The best things in life are free.

redsock2

  • Guest
Re: VBS:Malware-gen
« Reply #184 on: November 03, 2008, 02:15:10 PM »
Yes, I am impressed, really!!!
Thank you...
I Will reccomend Avast now :-))

I ask myself , why the equilibri admins dont realize this
script and remove it, its obvious in the htmlsource..
also it only appears on their main page, strange..

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #185 on: November 03, 2008, 03:18:29 PM »
Yes, strange indeed, if it is something they know about then you would have to ask why the hidden, encrypted data in javascript, what is a plain language script, what have they to hide. Either that or they are unaware that their home page has been hacked.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

dalonzolaw

  • Guest
Re: VBS:Malware-gen
« Reply #186 on: December 17, 2008, 03:32:38 PM »
Hello,

I have a VBS:Malware-gen

when I access hxxp://www.asdaurora-pregnana.it

VPS Version :  081217-0

can anybody help me ?

thans

iussi
« Last Edit: December 17, 2008, 08:17:56 PM by kubecj »

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #187 on: December 17, 2008, 03:54:37 PM »
There is a encrypted javascript at the end of the page, almost certainly a malware, I'd not consider that a FP.

buyog

  • Guest
Re: VBS:Malware-gen
« Reply #188 on: December 17, 2008, 07:58:35 PM »
I have the same problem

Avast popups when going to the site
hXXp://kentvoice.com

Screenshot here:
http://root.joshmir.com/vbs-malware.png

Thanks
« Last Edit: December 17, 2008, 08:17:36 PM by kubecj »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: VBS:Malware-gen
« Reply #189 on: December 17, 2008, 08:00:52 PM »
buyog, nowadays, avast malware detection on webpages is quite accurate... take care!
The best things in life are free.

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #190 on: December 17, 2008, 08:17:04 PM »
Large, encrypted stuff at the end of the page, most likely the malware.

Remember:
a) you can catch the bad stuff even from legitimate pages
b) Using MSIE can get you in trouble, avoid it if possible.

Casaboontha

  • Guest
Re: VBS:Malware-gen
« Reply #191 on: January 01, 2009, 10:44:49 PM »
a belated thank you to DavidR for pointing out the code!
I was able to fix my website. Thanks and a happy and prsperous 2009!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #192 on: January 01, 2009, 11:03:56 PM »
You're welcome and a Happy New Year to you too.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

barmon

  • Guest
Re: VBS:Malware-gen
« Reply #193 on: January 03, 2009, 01:16:34 AM »
Hi

I have avast home and everytime I go to this site:  http://www.clownclicks.com avast pops up for me to abort connection.

It says Malware name: VBS:Obfuscated-gen [trj]

Malware type:  Trojan Horse

VPS version:  090102-0, 01/02/2009

This does not appear in any other sites I go to, just to clownclicks.com
Never had any problems going to clownclicks.com and this virus warning just started about 30 min ago

I asked 3 friends to pull up clownclicks.com and they tell me they do not get any virus warnings.
So why me????

Hope to get answers, thanks!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: VBS:Malware-gen
« Reply #194 on: January 03, 2009, 01:22:51 AM »
Hi I scanned it with DrWeb's link checker:
Checking: http://www.clownclicks.com/
Engine version: 4.44.0.9170
File size: 10.84 KB

http://www.clownclicks.com/ - Ok

Checking: http://www.clownclicks.com/functions.js
File size: 7390 bytes

Went there with flock browser and NoScript temporarily allowing that site, no alerts (not from avast). So there must be something else wrong. Is your java version up to date?

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!