Author Topic: JS:Packed-AB [Trj].  (Read 7737 times)

0 Members and 3 Guests are viewing this topic.

altavistasf

  • Guest
JS:Packed-AB [Trj].
« on: February 01, 2009, 12:03:52 PM »
Avast DID infact detect the new malicious malware "JS:Packed-AB [trj]" but was unable to get rid of it. so why would avast post announcements that their antivirus is the ONLY one in the market to detect thsi new malware, while in fact is unable to remove it????
also, no postings on how to remove this malware on this website >:(

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9412
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: JS:Packed-AB [Trj].
« Reply #1 on: February 01, 2009, 02:12:11 PM »
Erm, use boot-time scan...
Also if you read closely it says they are the only ones detecting it fully, not removing it fully. Though boot time should do it.
« Last Edit: February 01, 2009, 02:14:08 PM by RejZoR »
Visit my webpage Angry Sheep Blog

altavistasf

  • Guest
Re: JS:Packed-AB [Trj].
« Reply #2 on: February 01, 2009, 02:17:26 PM »
you Eastern Europeans are definitely the ***SMARTEST*** i ve ever come across :)
Thanks for the suggestion. One question; how do i do the boot-time scan?

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: JS:Packed-AB [Trj].
« Reply #3 on: February 01, 2009, 02:20:38 PM »
and how could we fix/clean the server-side infections, when we are on the client side? don't you know? should we hack the server, clean the html pages and go away? :P

micky77

  • Guest
Re: JS:Packed-AB [Trj].
« Reply #4 on: February 01, 2009, 03:18:43 PM »
you Eastern Europeans are definitely the ***SMARTEST*** i ve ever come across :)
Thanks for the suggestion. One question; how do i do the boot-time scan?

http://www.digitalred.com/avast-boot-time.php

L

  • Guest
Re: JS:Packed-AB [Trj].
« Reply #5 on: February 01, 2009, 05:11:47 PM »
I have encountered a JS:Packed-D [trj] every time an add for Cisco Collaboration Technologies comes on while watching a show on fox.com. It causes Firefox to crash. How do I get past it?

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9412
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: JS:Packed-AB [Trj].
« Reply #6 on: February 01, 2009, 08:04:26 PM »
You can't because it's apparently embeded inside that advertisement. Well you can try with AdBlock Plus extension however to block the ads all together and also avoid loading that ad.
Visit my webpage Angry Sheep Blog

sert

  • Guest
Re: JS:Packed-AB [Trj].
« Reply #7 on: February 02, 2009, 04:02:13 PM »
Avast DID infact detect the new malicious malware "JS:Packed-AB [trj]" but was unable to get rid of it. so why would avast post announcements that their antivirus is the ONLY one in the market to detect thsi new malware, while in fact is unable to remove it????
also, no postings on how to remove this malware on this website >:(
avast is not the ONLY one in the market to detect this new malware, Sophos detects it as JS/ApndIfra-A since 11 April 2008, avast should not say that

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: JS:Packed-AB [Trj].
« Reply #8 on: February 02, 2009, 04:24:44 PM »
It wouldn't be new if it was from April 2008, there are new variants and attack methods coming out, so I feel sure this doesn't refer to the same thing.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: JS:Packed-AB [Trj].
« Reply #9 on: February 02, 2009, 04:58:37 PM »
sert: the phrase is "At the moment, avast! is the only antivirus software fully detecting this new malware." - you probably overlooked the word FULLY... some sites detected by our engine were checked against other AV engines and not a single one of them has had a 100% coverage... this was the statement on Jan 18.

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: JS:Packed-AB [Trj].
« Reply #10 on: February 02, 2009, 05:50:22 PM »
well... At the time of publishing avast was only one AV protecting against this malware. It is more than 14 days now, so what has changed?

Sophos looks to be the second engine (GData uses avast!, so GData too). Sophos detect this malware as Mal/ObfJS-AJ which is probably some generic detection. Description can be seen here:
Code: [Select]
http://www.sophos.com/security/analyses/viruses-and-spyware/malobfjsaj.html
Dates from description says everything, so this looks sophos generic detections maight detect this malware before avast.

And how looks todays detections (more than 14 days after attack):
Code: [Select]
http://www.virustotal.com/cs/analisis/ccb0c368459322acd008d024e361a458
http://www.virustotal.com/cs/analisis/470fe4182ca7d5682dfaa6f8a8737ee5

Both files are real webpages downloaded from internet.

Regards