http://tuserie.com - Avast detects: JS:ScriptIP-inf [Trj]

Dear friends.

The Avast Free Antivirus is blocking the Web Page mentioned on the subject, despite I selected it as be excluded.
Please help me to unlock it. I don´t want to uninstall the Avast.

Thanks & Regards.

Hugo Arias

Yes and because of this exploit: https://gist.github.com/jasongill/2523147
Suspicious external shortener links: http://adf.ly/vexlb → avast bad web rep alert

polonus

How can avoid it?

Probably by adware blocking, as it is adware injecting. In the past the uninstall of a toolbar cured these alerts.

polonus

Polonus:

Thank you for your replay, but excuse my ignorance. How can I do the adware blocking?
It is an Avast setting or in the Intertet Explorer?

Regards,

Hugo

Try this…

Clear your browsers with AdwCleaner http://www.bleepingcomputer.com/download/adwcleaner/

Then run malwarebytes and remove evrything it find https://forum.avast.com/index.php?topic=53253.0

Post logs here…

Did that solve it?

AdwCleaner v4.106 - Reporte Creado 29/12/2014 en 13:10:30

Actualizado 21/12/2014 por Xplode

Database : 2014-12-28.1 [Live]

Sistema Operativo : Windows 8 Pro (64 bits)

Nombre de usuario : B590 - USER

Ejecutado desde : C:\Users\B590\Downloads\adwcleaner_4.106.exe

Opción : Limpiar

***** [ Servicios ] *****

Servicio Borrar : {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64

***** [ Archivos / Carpetas ] *****

Carpeta Borrar : C:\ProgramData\apn
Carpeta Borrar : C:\ProgramData\AskPartnerNetwork
Carpeta Borrar : C:\Program Files (x86)\AskPartnerNetwork
Carpeta Borrar : C:\Program Files (x86)\IminentToolbar
Carpeta Borrar : C:\Users\B590\AppData\Local\AskPartnerNetwork
Carpeta Borrar : C:\Users\B590\AppData\LocalLow\IminentToolbar
Carpeta Borrar : C:\Users\B590\AppData\Roaming\EZDownloader
Carpeta Borrar : C:\Users\B590\AppData\Roaming\IminentToolbar
Carpeta Borrar : C:\Users\B590\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Archivo Borrar : C:\Windows\System32\drivers{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys
Archivo Borrar : C:\Users\B590\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Archivo Borrar : C:\Users\B590\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage

***** [ Tareas ] *****

***** [ Accesos directos ] *****

***** [ Registro ] *****

Clave Borrar : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{44CBC005-6243-4502-8A02-3A096A282664}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{80703783-E415-4EE3-AB60-D36981C5A6F1}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{D8278076-BC68-4484-9233-6E7F1628B56C}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID{F297534D-7B06-459D-BC19-2DD8EF69297B}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{021B4049-F57D-4565-A693-FD3B04786BFA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{06844020-CD0B-3D3D-A7FE-371153013E49}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{10D3722F-23E6-3901-B6C1-FF6567121920}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{1675E62B-F911-3B7B-A046-EB57261212F3}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{192929F2-9273-3894-91B0-F54671C4C861}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{2932897E-3036-43D9-8A64-B06447992065}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{32B80AD6-1214-45F4-994E-78A5D482C000}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{72227B7F-1F02-3560-95F5-592E68BACC0C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{80703783-E415-4EE3-AB60-D36981C5A6F1}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{8C68913C-AC3C-4494-8B9C-984D87C85003}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{923F6FB8-A390-370E-A0D2-DD505432481D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{D25B101F-8188-3B43-9D85-201F372BC205}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib{9945959C-AAD8-4312-8B57-2DE11927E770}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{68B81CCD-A80C-4060-8947-5AE69ED01199}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{D7949A66-D936-4028-9552-14F7DC50F38D}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{021B4049-F57D-4565-A693-FD3B04786BFA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{06844020-CD0B-3D3D-A7FE-371153013E49}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{10D3722F-23E6-3901-B6C1-FF6567121920}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{1675E62B-F911-3B7B-A046-EB57261212F3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{192929F2-9273-3894-91B0-F54671C4C861}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{2932897E-3036-43D9-8A64-B06447992065}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{32B80AD6-1214-45F4-994E-78A5D482C000}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{72227B7F-1F02-3560-95F5-592E68BACC0C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{8C68913C-AC3C-4494-8B9C-984D87C85003}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{923F6FB8-A390-370E-A0D2-DD505432481D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{D25B101F-8188-3B43-9D85-201F372BC205}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Clave Borrar : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{D7949A66-D936-4028-9552-14F7DC50F38D}
Clave Borrar : HKCU\Software\AskPartnerNetwork
Clave Borrar : HKCU\Software\Softonic
Clave Borrar : HKLM\SOFTWARE\Iminent
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Clave Borrar : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Clave Borrar : [x64] HKLM\SOFTWARE\Iminent
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75FF6D97AF9FC004A9521D4B83FA6321
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB13D869D7D092348847B7481BB59E27
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7

***** [ Navegadores ] *****

-\ Internet Explorer v10.0.9200.16384

-\ Google Chrome v39.0.2171.95

[C:\Users\B590\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Borrar [Search Provider] : hxxp://www.softonic.com/s/{searchTerms}


AdwCleaner[R0].txt - [13604 octets] - [29/12/2014 13:02:47]
AdwCleaner[R1].txt - [13810 octets] - [29/12/2014 13:07:37]
AdwCleaner[S0].txt - [12857 octets] - [29/12/2014 13:10:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12918 octets] ##########

Malwarebytes Anti-Malware does not find any malware, but the web page of the subject continues giving the virus alert.
I hate it, this is one of my favorite pages and now I could not access it. I will try tomorrow. Thanks anyway.

Page is still blocked. Have you another idea to fix it? Thanks.

The malcode is detected here: htxp://b117f8da23446a91387efea0e428392a.pl/scripts/ws1506.min.js?b=20141222&cd=
→ b117f8da23446a91387efea0e428392a.pl,188.165.55.191,dns108.ovh.net,Criminals,
WOT also flags: https://www.mywot.com/en/scorecard/b117f8da23446a91387efea0e428392a.pl?utm_source=addon&utm_content=popup
Issues: http://www.dnsinspect.com/b117f8da23446a91387efea0e428392a.pl/1419947463

polonus

I guess that means that I can not do nothing until the webmaster of the web page fix it.

Yep, see the warnings here: http://www.avgthreatlabs.com/website-safety-reports/domain/b117f8da23446a91387efea0e428392a.pl/
here it hasd got a safe check: http://safecheck.find-my-search.com/en/safe-checking-of/b117f8da23446a91387efea0e428392a.pl/
Recent badness history on IP: https://www.virustotal.com/nl/domain/b117f8da23446a91387efea0e428392a.pl/information/

polonus

Thanks. I will be patience and wait for it. Regards.