Feedback: Avast Anti-virus reporting a trojan horse...

  • After Iowa State won the Big 12, a Cyclone made a wonderful offer to We Will that now increases our match. Now all gifts up to $400,000 between now and the Final 4 will be matched. Please consider giving at We Will Collective.
    This notice can be dismissed using the upper right corner X button.

drednot57

Well-Known Member
Apr 26, 2010
2,036
180
63
66
Nevada, IA
from an affiliated site (?): http://cerabos.co.be/index.php?tp=0c9b13a3940500bc -- looks to be located in Belgium?

Malware: JS:Downloader-AQW.

You guys may have one or more advertisers proliferating malware on your site; please check them out.

Thanks. :smile:

Edit: Just did a nslookup, and it reported ip addresses 63.251.179.32, and 64.27.117.56. Hope this helps.
 
Last edited:

Wesley

Well-Known Member
Apr 12, 2006
70,923
546
113
Omaha
I second that emotion. Please check out those cads from Belgium.
 
Last edited:

hawkeyeh8r

Well-Known Member
Jun 10, 2010
2,159
46
48
34
Ames
hmm avg and avast are now picking it up. im surprised my avg AV hasnt picked anything up yet
 

ianoconnor

Well-Known Member
SuperFanatic
SuperFanatic T2
Nov 11, 2007
13,132
6,881
113
Johnston
I got a virus here yesterday on my work computer and it just popped up again now. Its the 'windows xp restore' virus.
 

ItsCyence

Well-Known Member
SuperFanatic
SuperFanatic T2
Apr 28, 2010
3,768
377
83
Sioux City
Hmm I haven't received a warning ever on this site. Does that mean my Norton is good?
 

isuno1fan

Well-Known Member
Mar 30, 2006
22,829
4,353
113
Clive, Iowa
I mentioned in another thread it is exactly the same thing that happened last Summer. Should be easy to fix. Has happened twice to me today.

CW says they are on it, I guess I'll take his word for it.
 

BenEClone

Well-Known Member
Mar 21, 2006
2,667
339
83
Lincoln, Ne
Hey guys - Does your virus protections say anything about where this virus is being found? Any details on that would help.

This is what popped up for me on the main page, I have no idea what it means:

block-doc.gif
Danger: Surf-Shield has detected active threats on this page and has blocked access for your protection.


The page you are trying to access has been identified as a known exploit, phishing, or social engineering web site and therefore has been blocked for your safety. Without protection, such as that in the AVG Security Toolbar and AVG, your computer is at risk of being compromised, corrupted or having your identity stolen. Please follow one of the suggestions below to continue.

URL: dollhop.co.be/index.php?tp=f2aac5514568eb04
Name: Blackhole Exploit Kit (type 2021)
 

SeattleClone

Well-Known Member
Aug 15, 2006
6,189
452
83
CF has been getting flagged by Norton several times over the last couple days.

193.105.154.238 dergale.co.be

I think I'm about done here... I definitely do not want something getting past Norton on my new computer, and I'll be switching to avast when my Norton trial is over. This keeps happening way too often here. I frequent several other message board websites with no problems.
 

RustShack

Chiefs Dynasty
SuperFanatic
SuperFanatic T2
Jan 27, 2010
13,248
7,435
113
Overland Park
I don't get it anymore.. whatever ad it is my adblock on firefox must block it because it stopped after I updated that.
 

2020cy

Well-Known Member
Aug 7, 2006
6,224
2,472
113
I got nailed on my laptop, not fixed yet. Still issues as of Friday night.
 

shawn_200m

Active Member
Apr 10, 2006
824
227
43
Tipton, IA
I got nailed tonight with this virus and it wiped out my hard drive...all of my files are gone. I'm officially done here, completely ridiculous....posting this from my phone.