Author Topic: hpHosts Blog and avast! Pop-Up Trojan!  (Read 4793 times)

0 Members and 1 Guest are viewing this topic.

hayc59

  • Guest
hpHosts Blog and avast! Pop-Up Trojan!
« on: December 14, 2011, 02:39:03 AM »
Might this be a false positive?
everytime I go there starting last night
I get that pop-up
*see image
thanks for any and all help

Infection: js:Downloader-BDP [Trj]

Code: [Select]
http://hphosts.blogspot.com/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #1 on: December 14, 2011, 07:55:29 AM »
« Last Edit: December 14, 2011, 07:58:39 AM by Pondus »

Tetsuo

  • Guest
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #2 on: December 14, 2011, 12:12:03 PM »
It might be a FP. Not sure why urlQuery says "Suspicous" though...

YoKenny

  • Guest
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #3 on: December 14, 2011, 03:41:46 PM »
could be it is detecting on something posted in the blog ?

It is definitely something in the blog!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89124
  • No support PMs thanks
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #4 on: December 14, 2011, 05:01:47 PM »
It might be a FP. Not sure why urlQuery says "Suspicous" though...

The Suspicious, if you checked out the URLQuery link is Reputation based, which would seem a bit strange for either blogspot or HpHosts sub-domain, though you get all sorts of dross using blockspot.com for their blog.

That said there is a compressed script file being loaded when you open that hphosts.blogspot.com/ page, as indicated by the |>{gzip} at the end of the alert URL and it is this that avast doesn't like, see image extract of the file contents.

Having said that subsequent visits I don't get the alert (after the web shield aborted the connection, for the gzip element)
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

hayc59

  • Guest
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #5 on: December 18, 2011, 03:34:19 AM »
thank you and Dave...where did you find that file?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89124
  • No support PMs thanks
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #6 on: December 18, 2011, 01:34:06 PM »
It is the compressed file that otherwise would be loaded/run when you use that blogspot.com link, a temporary file is created by avast to scan, I captured that.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Tetsuo

  • Guest
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #7 on: December 18, 2011, 02:07:48 PM »
It is the compressed file that otherwise would be loaded/run when you use that blogspot.com link, a temporary file is created by avast to scan, I captured that.

I forgot where Avast places the unp*.tmp file. Not sure if it's in windows/temp or elsewhere...
« Last Edit: December 18, 2011, 02:14:43 PM by Tetsuo »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89124
  • No support PMs thanks
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #8 on: December 18, 2011, 03:58:09 PM »
It is the _avast_ sub-folder of windows\temp

Though for obvious reasons, playing with suspect files comes with the usual health warning and disclaimer.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Tetsuo

  • Guest
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #9 on: December 18, 2011, 04:06:25 PM »
Thanks, DavidR.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89124
  • No support PMs thanks
Re: hpHosts Blog and avast! Pop-Up Trojan!
« Reply #10 on: December 18, 2011, 04:12:28 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security