system
August 28, 2017, 1:28pm
1
Since days I often get messages
The pop-up says:
Object:
https://ad.adtr.02.com/js/ad.js?v=72
Infection:
JS:Downloader-DEF [Trj]
Process:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Have tried adwcleaner, CCleaner and Malwarebytes - no success
Get this message mostly on ebay site
Eddy
August 28, 2017, 1:40pm
2
Pondus
August 28, 2017, 1:41pm
3
ad.adtr.02.com/js/ad.js?v=72 seems to be down >> https://isitdownorjust.me/ad-adtr-02-com/
Not sure if CCleaner empty firefox cache, but you may try this >> https://support.mozilla.org/en-US/kb/how-clear-firefox-cache
If still problem follow instructions in the link Eddy posted
DavidR
August 28, 2017, 2:18pm
4
I used another site checker and only used the top level domain, 02.com no sub-domains and that too suggests it is down for everyone. Even the full sub.domain URL ad.adtr.02.com results in the same down for everyone.
http://downforeveryoneorjustme.com/02.com
savcin
August 28, 2017, 3:09pm
5
Can you please submit particular file?
system
August 28, 2017, 6:49pm
7
system
August 28, 2017, 7:30pm
8
again… (whilst on ebay site)
Pondus
August 28, 2017, 7:33pm
9
The malwarebytes log you attached is not the scan log, anyway if nothing was detected there is no need for it
Malware experts are notified, they may not be online before tomorrow
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
GroupPolicy: Beschränkung - Chrome <==== ACHTUNG
GroupPolicyScripts: Beschränkung <==== ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG
OPR Extension: (Video Downloader Prime) - C:\Users\rw\AppData\Roaming\Opera Software\Opera Stable\Extensions\diefijfleiebcgdkmaefbjehgcokpdjl [2016-12-16]
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
Tell me, does Avast blocks that URL while surfing in Chrome and if possible, paste here URLs which are currently opened in browser when you get Avast message.
system
August 29, 2017, 5:24am
11
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
GroupPolicy: Beschränkung - Chrome <==== ACHTUNG
GroupPolicyScripts: Beschränkung <==== ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG
OPR Extension: (Video Downloader Prime) - C:\Users\rw\AppData\Roaming\Opera Software\Opera Stable\Extensions\diefijfleiebcgdkmaefbjehgcokpdjl [2016-12-16]
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
Tell me, does Avast blocks that URL while surfing in Chrome and if possible, paste here URLs which are currently opened in browser when you get Avast message.
fixlog.txt attached
Okay, I´ll try Chrome for some time today.
system
August 29, 2017, 6:02am
12
savcin
August 29, 2017, 1:05pm
14
Very strange obfuscation is used. :-\
Eddy
August 29, 2017, 1:18pm
15
Just checked both links in reply #11 and no warnings with Opera 47.0.2631.71 (PGO) on W10 (fully up to date) and latest avast free.
Just a guess, but perhaps because the ads are “targeted”.
Searching for adtr in the source code gives 0 results.
system
August 29, 2017, 2:36pm
16
Meanwhile I know from the German Avadas Forum (http://forum.avadas.de/threads/8095-ständige-Meldung-Bedrohung-durch-quot-JS-Downloader-DEF-quot ) that there are at least two other users with the same problem as mine
Eddy
August 29, 2017, 2:38pm
17
There is also a post about it on the MAC forum.
https://forum.avast.com/index.php?topic=207906.0
avadas.de is NOT the German avast forum/webboard.
Logs say that your system is clean which means you don’t have adware on your system which cause Avast to block mentioned JS. I’m still waiting for this VirusTotal scan finishes and until then we will not know for sure is it Avast false positive or not.
https://www.virustotal.com/#/file-analysis/MjE1ZjMwYWYzMTY1NWYxMmZlOTgxODcwODI2M2I2YjQ6MTUwNDAzNzIyNQ==
http://r.virscan.org/report/9ca20a9db021ed64aad9df7ebb3e1488
EDIT: As for targeting, Germany is targeted as far as I know.
EDIT2:
Buggy VT: https://www.virustotal.com/#/file/9e086ce4bbc3aa9e89823af5fa43c591ae152e261f35d035b64d135436b0b820/detection
system
August 31, 2017, 8:13am
20
Obviously the problem has been solved - no more alerts in this case since yesterday. Fine