Author Topic: http://aggregateknowledge.net/www/cmd/s/5.0  (Read 5215 times)

0 Members and 1 Guest are viewing this topic.

Offline What?

  • Newbie
  • *
  • Posts: 6
http://aggregateknowledge.net/www/cmd/s/5.0
« on: September 25, 2010, 02:41:46 AM »
Hi.
I'm a newbie here.
 I keep getting a warning from Avast complaining about this address. Of course I'M not trying to go there, it's something in the background doing it. It says its a Trojan.
JS: Treffuc-C[Trj] specifically.  

See attached screen shot.

It goes off every so often as I surf or get into my hotmail account - but random.

Is it false? I can't find any info about it out there on the web, nor here. I can't be the first one if it were truly a Trojan, could I?  Anyway, only annoying for now.
So far I have only "aborted connection" when it appears.
The second attachment here is from the log. The items in the yellow box is from a few months ago and hasn't been warning me.

Thanks
« Last Edit: September 25, 2010, 02:57:37 AM by What? »

karma2m

  • Guest
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #1 on: September 25, 2010, 06:31:17 AM »
you're not alone- been getting this for a weeks when reading news on MSN using Firefox.

Sartigan

  • Guest
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #2 on: September 25, 2010, 10:39:52 AM »
It seems to be a false positive: http://www.virustotal.com/file-scan/report.html?id=695e269c7cb6389ef051aaaf900edd1830a8abd00e28509ac30c9009ae36f5fe-1285403807

But you should check the running processes.

...and as I see, you have avast! 4.8, upgrade to 5.0 which is better than 4.8
« Last Edit: September 25, 2010, 10:51:09 AM by Sartigan »

kirts

  • Guest
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #3 on: September 25, 2010, 04:22:31 PM »
Add me to this list.  I get this same exact error all over msnbc.com.  Doesn't matter if I use Firefox 3.6.10 or IE8.  Seems like a false positive.  Hopefully they'll fix it soon.  It's annoying.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89149
  • No support PMs thanks
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #4 on: September 25, 2010, 05:46:35 PM »
It seems to be a false positive: http://www.virustotal.com/file-scan/report.html?id=695e269c7cb6389ef051aaaf900edd1830a8abd00e28509ac30c9009ae36f5fe-1285403807
<snip>

If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.

Have you sent the sample to avast for analysis:
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.

Edit: I have just tried to visit hxxp://aggregateknowledge.net and I get a blank page, so it looks like they might have taken the site down ?
« Last Edit: September 25, 2010, 05:49:57 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline What?

  • Newbie
  • *
  • Posts: 6
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #5 on: September 26, 2010, 08:25:11 PM »
No I get the same. It merely won't let you actually go to a site like that. I this its a statistic reporting site or the likes (Like malware?).

I'll see if I can send from chest.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #6 on: September 26, 2010, 08:39:27 PM »
Hi malware fighters,

TrendMicro also detects it as suspicious, so not only avast and GData...
Then there is this source: http://blearc.newsvine.com/_news/2010/09/24/5173862-trojans-on-newsvine
And this could be a rootkit trojan, according to this source:
http://www.bleepingcomputer.com/forums/lofiversion/index.php/t43051.html[/t136502.html
finjan does not detect: The requested URL was analyzed and found legitimate
But when launched with Malzilla redirection is detected...Redirects

From                                           To
htxp://aggregateknowledge.net/www/cmd/s/5.0   htxp://aggregateknowledge.net/www/cmd/s/5.0/


polonus
« Last Edit: September 26, 2010, 08:40:59 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline What?

  • Newbie
  • *
  • Posts: 6
Re: http://aggregateknowledge.net/www/cmd/s/5.0
« Reply #7 on: September 27, 2010, 02:55:15 AM »

Have you sent the sample to avast for analysis:
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.


I find no actual file for submission in the chest. This issue is being stopped prior to getting any file from this suspicious web address I guess. A full system AV scan finds no virus on my PC - nor did it ever, in this case.