Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Solved: Avast detects a redirector?

Reply  
Thread Tools
DKTaber's Avatar
Computer Specs
Senior Member with 1,951 posts.
 
Join Date: Oct 2001
Location: Wilmington, DE
Experience: Advanced
08-May-2009, 09:04 AM #1
Solved: Avast detects a redirector?
Friend has Avast! on her Vista laptop. Yesterday, she was looking at some genealogy sites, and opened delgensoc.org/dgswork03.htm and instantly got a warning from Avast! that it had discovered the trojan JS:Redirector-H4. Instructed Avast! to delete it, which it did.

My AV is Avira Antivir (ver. 9) and my OS is Win XP. I went to the same site on my computer, and no warning. A subsequent full AV scan detected no viruses (also did full scans with Ad-aware anniversary edition, SuperAntiSpyware, and Malwarebytes. None found anything).

So my questions are: Is there any such trojan as JS:Redirector-H4? Could it really be on the Web site? Or is this a false positive from Avast!?

If you use Avast!, when you go to the site mentioned above, does it give you a warning?
__________________
Win XP SP3 32-bit; Intel DQ35JO mobo w/E8400 Core 2 Duo; 2GB RAM; 500GB HD; Comcast; D-Link DIR 601 router. Also, Toshiba Core i5 Win 7 laptop.
Sail on Delaware's Tall Ship Ambassador, Kalmar Nyckel

Last edited by Cookiegal; 08-May-2009 at 01:50 PM.. Reason: To disable link
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
08-May-2009, 09:21 AM #2
My kaspersky also seemed to block something out of place
Attached Thumbnails
Solved: Avast detects a redirector?-kis.gif  
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
08-May-2009, 09:23 AM #3
So my answer is yes, the site contains a trojan redirector
Kenny94's Avatar
Account Disabled with 2,481 posts.
 
Join Date: Dec 2004
Location: S.C
08-May-2009, 09:31 AM #4
The site seems fine on my computer. I'm using Nod32.. And Wot gives the site a green light....
DKTaber's Avatar
Computer Specs
Senior Member with 1,951 posts.
 
Join Date: Oct 2001
Location: Wilmington, DE
Experience: Advanced
08-May-2009, 09:49 AM #5
Quote:
Originally Posted by Kenny94 View Post
The site seems fine on my computer. I'm using Nod32.. And Wot gives the site a green light....
Yeah, so does mine. But see the messages above from srprashant. Kaspersky, a very highly rated AV, also says it's a rogue site. IMO, this confirms that it is. I am disappointed that my Avira, for which I also have a high opinion, didn't flag it. Nor does WOT put a red light on it.

I don't think the site purposely has the trojan; I think it was hacked. I have sent a notification to WOT about it.

Thanks for the quick responses.
__________________
Win XP SP3 32-bit; Intel DQ35JO mobo w/E8400 Core 2 Duo; 2GB RAM; 500GB HD; Comcast; D-Link DIR 601 router. Also, Toshiba Core i5 Win 7 laptop.
Sail on Delaware's Tall Ship Ambassador, Kalmar Nyckel
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
08-May-2009, 09:55 AM #6
It may also be a false positive from Kaspersky.

If Avast has detected it and not NOD32, I would say there's nothing to worry about...
Kenny94's Avatar
Account Disabled with 2,481 posts.
 
Join Date: Dec 2004
Location: S.C
08-May-2009, 10:02 AM #7
Kaspersky is know to be over cautious. But I do like Kaspersky..
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
08-May-2009, 10:04 AM #8
Kaspersky is a good product and would be my second choice but as Kenny94 says, it's a little over cautious...
DKTaber's Avatar
Computer Specs
Senior Member with 1,951 posts.
 
Join Date: Oct 2001
Location: Wilmington, DE
Experience: Advanced
08-May-2009, 10:09 AM #9
Quote:
Originally Posted by Phantom010 View Post
It may also be a false positive from Kaspersky.

If Avast has detected it and not NOD32, I would say there's nothing to worry about...
Perhaps. As I said, I sent a message to WOT suggesting they investigate. If I hear back from them, I'll post it here. If it turns out to be a false positive, my faith in Avira will be restored. If the site DOES contain the trojan Kaspersky says it does (and where would it get such detailed information if it's a false positive; look at the attachment to srprashant's first response), I'll have to reassess my commitment to Avira.
__________________
Win XP SP3 32-bit; Intel DQ35JO mobo w/E8400 Core 2 Duo; 2GB RAM; 500GB HD; Comcast; D-Link DIR 601 router. Also, Toshiba Core i5 Win 7 laptop.
Sail on Delaware's Tall Ship Ambassador, Kalmar Nyckel
Kenny94's Avatar
Account Disabled with 2,481 posts.
 
Join Date: Dec 2004
Location: S.C
08-May-2009, 10:13 AM #10
Avira has make a lot of progess in the past year. And I have it my top Antivirus list now.
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
08-May-2009, 10:18 AM #11
If you carefully read the Kaspersky pop-up, it's a warning about a web page that is used to steal passwords... It's not detecting any malware... It's a bit like a McAfee Site Advisor.

Last edited by Phantom010; 08-May-2009 at 10:36 AM.. Reason: stupid misinterpretation
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,289 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
08-May-2009, 10:32 AM #12
Actually, it means that it is used to steal passwords, not in the past tense.

This is a new and real web site exploit that I would take seriously. It seems to be using either javascript, pdf, flash or iframe exploits to redirect to that malicious site.

Someone should contact the site owners that they should check their pages.
__________________
Microsoft MVP - Consumer Security
DKTaber's Avatar
Computer Specs
Senior Member with 1,951 posts.
 
Join Date: Oct 2001
Location: Wilmington, DE
Experience: Advanced
08-May-2009, 10:36 AM #13
Quote:
Originally Posted by Phantom010 View Post
If you carefully read the Kaspersky pop-up, it's a warning about a web page that used to steal passwords... It's not detecting any malware either... It's a bit like a McAfee Site Advisor.
I don't read it that way at all. It says the Web page "contains a link to a Web page [that is] used to steal...confidential data..." Said another way, "a Web page [whose purpose is] to steal...confidential data..."
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
08-May-2009, 10:38 AM #14
Quote:
Originally Posted by DKTaber View Post
I don't read it that way at all. It says the Web page "contains a link to a Web page [that is] used to steal...confidential data..." Said another way, "a Web page [whose purpose is] to steal...confidential data..."
Forget about my misinterpretation of the "used". I didn't have my coffee yet.


Last edited by Phantom010; 08-May-2009 at 10:44 AM..
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
08-May-2009, 10:48 AM #15
I take a note of what cookiegal says. The exploit on the website could take advantage of vulnerabilities and could launch various attacks.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:40 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.