Avast is blocking a trojan but I can't find it

Hello, I hope someone can help.

Since yesterday, I have been receiving an alert that a trojan has been blocked. The trojan is JS:IFrame-AC which I think is a downloader. The source of the trojan seems to be e-merl dot com, a site I visited briefly without incident. The alerts only started some time later.

I have run scans with avast, MBAM, spybot s&d, housecall and even Windows Defender all of which found nothing. I ran HiJack This, although it couldn’t access the hosts file or create a log. I have tried every way I know to elevate it to administator and it wont let me. I’m not sure if the alert is some kind of false positive, or a glitch or if there is a trojan on my laptop. Any advice would be greatly appreciated.

Thanks

hoop

hXXp://e-merl.com/feed is very infected according to Sucuri Scanner
Known javascript malware. Details: http://sucuri.net/malware/malware-entry-mwjs444

looks as you may have something in there that is trying to connect to this site ?

VirusTotal - feed.xml - 8/42
http://www.virustotal.com/file-scan/report.html?id=f7295f5443f6db8e9dc2021ff9250951a7f068761a5eda638e00ce905d9caeee-1309905899

Thanks for the help Pondus. It does seem like that website is bad. I had thought the source was actually a different website. But I must have jumped to the wrong conclusion because it seems it is an RSS feed to a webcomic that I actually haven’t visited in a while. I’ve deleted that feed from my bookmarks. I think the alert probably was coming up every time the feed tried to reload itself.

Anyway, I ran aswMBR as you suggested. The logfile is attached.

Thanks again

hoop

Lets see if we can find the miscreant

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop

[*]Close ALL OTHER PROGRAMS.
[*]Double-click on OTS.exe to start the program.
[*]Check the box that says Scan All Users
[*]Under Additional Scans check the following:

Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

[*]Under the Custom Scan box paste this in


%SYSTEMDRIVE%*.exe
/md5start
volsnap.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

[*]Now click the Run Scan button on the toolbar.
[*]Let it run unhindered until it finishes.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Please attach the log in your next post.

Hi essexboy, thanks for taking the time to help me out. I’ve attached the OTS log as requested.

Since I deleted the old RSS feed from e-merl I haven’t had any more alerts, and scans still come up clear. One odd thing has happened though: the scroll function on the touchpad of my laptop has stopped working. A .dll which controls it (?) fails to load and an error message pops up to tell me about it. I suspect that this is just a coincidence, but I don’t want to try and fix that until I know there is no malware sneaking around. I thought I’d mention it anyway, on the off chance it’s significant.

Cheers

hoop

That looks OK - what is the dll referenced ? I will see if I can get a spare for you ;D

Yay! Thanks so much that’s a weight off. Really appreciate you guys taking a look at my problem.

The dll that fails to load is lanucher.dll a component of Apoint.exe. Seems I didn’t know I’d miss it until it was gone. Or that it existed to be honest ;D

Thanks again essexboy and Pondus

hoop

Could you go to my site here https://skydrive.live.com/?cid=32d8666f4048075b&sc=documents&uc=1&id=32D8666F4048075B!117
and download the file Launcher.zip
Extract the file and then copy to the relevant directory (C:\windows\system32)

Thanks once again essexboy.

The new dll didn’t actually work, which struck me as odd. So I trawled through an old thread on the Dell Support forums and found out this is a common problem on Dell laptops that Dell are pretty useless at fixing (they suggest reinstalling the OS). No one seems to be sure what causes it or why it only stops working if you click OK in the error box. If you leave it alone the scroll continues to function. Weird. Anyway I uninstalled the driver and got a new one, elevated the driver software to administrator and stopped Defender from blocking the driver on startup. Seems to be working now.

Thanks for locating the dll for me, I probably would have continued to live in a scrolless universe otherwise.

hoop

;D Run OTS and hit the cleanup button to remove it

Thanks, I’ll do that. Everything seems to be running tickety boo now.

Oh except for being redirected to 64.111.211- ;D I kid.

Thanks for all your help, it’s been awesome.

hoop

Aaaaaargh ;D

Yep that is a bit of a pain at the moment - and each time so far it is something different

I’ve been following the threads. Seems like a pesky problem. It’s a good advert for being super careful about web security.

Hi,

I’m having the same problem on my dedicated server (windows server 2008 R2).

Can you please help me out essexboy? (It won’t let me message you)

I have avast anti virus server edition installed on a dedicated server running multiple websites. When I scan it picks nothing up. But I have a virus or malware somewhere that keeps injecting javascript into index.x, default.x and login.x webpages. I can restore them, remove the JS by hand and everything will be fine for a while, but during my weekly scan it will usually pick up the same files with the same JS (linking to different sites each time) and delete them to the virus chest.

Luckily none of the websites are live.

I wont lie, I often use remote desktop to access the server at work to bypass the strict firewall settings we have. But I just browse Facebook and a few forums, nothing dodgy…

Can you (or anyone else) help me out please?

The virus name is: “JS:IFrame-AC[Trj]”

Thank you.

@stoink… follow the guide here

http://forum.avast.com/index.php?topic=53253.0

start a new topic and attach the log`s and essexboy will have a look when he arrive

see the reply there from DavidR on how to start a new topic

Should be fun - I do not work many servers

I see this topic is almost a month old. I’ve been getting this same message for the past week on my message board.

if you have a virus problem start a new topic where you tell us what it is…
post as much info as you can…

you find the blue “NEW TOPIC” button in top right corner here when logged in http://forum.avast.com/index.php?board=4.0