Is U.A.E.'s (Dubai) No. 2 Portal (Dubizzle.com) Infected by Trojan???

Hi guys,

Can you please help me identify if the U.A.E.’s No. 2 (probably) portal has been compromised by a Trojan Horse virus?

A moment ago I’ve tried visiting this website dubizzle.com several times with different browsers but it all ended up with me having my AVAST (Free version) warned me about a Trojan Horse infection. Luckily the warning says that the threat was blocked. In all the websites that I’ve recently visited, the warning only showed up in this website alone.

Based on the warning it seems there was a Java script embedded in the website that triggers the infection, it is called (JS:Downloader-AFY )? I don’t know if I’m just the only one experiencing this or maybe my PC was the one who has been infected? I’m regularly visiting this website and it only happens to me just now.

What would you think? Is it safe for users to further browse this website? I’ve attached a screenshot of the said notification in order for you to check if it is just a false-positive?

The URL in the avast! warning is different then the one you posted. I get nothing on the one you posted but the one in the avast! warning gives this

VirusTotal - top_1286364087.js - 3/43
http://www.virustotal.com/file-scan/report.html?id=c5ec8fd089c4d45551b2abc9082744ba4ca673da3d62a3e8e5d3a93b8291baff-1286917346

Sorry, I didn’t get it? ;D

If I’m right you haven’t get any warning as per shown in the screenshot? If yes, why I’m getting it? Does it mean that the virus resides in my PC and not in the mentioned website?

Not with any online scanner, have not tried with avast!. And the virus is on the website, avast! blocked it

I get two alerts on that site, one from the web shield, and another one from the file system shield. Wondering how come that the web shield didn’t block everything ??? (apparently there’s an archive involved that complicated the task somehow…)

ps: @ the OP, can you deactivate your link by replacing http by hxxp?

I have now tried entering the above posted URL with avast! and IE8 / Chrome / Opera and no warning ???

okay the first test with two alerts was in IE9, I just retried with Firefox 4 and there’s only the web shield alert (with JS allowed to run on the site)… so there’s an issue between IE9 and the web shield it seems….

if you get nothing on the main page of the site, click a link on it.

Yes, click some links and you will get something, if not probably because of your AVAST version, mine is ver. 5.0.677…

okay, same in Chrome like in Firefox, just a web shield alert, meaning that there’s a flaw somewhere allowing malware to partially bypass the web shield in IE9.

OK clicking links give alarm with IE8 and Chrome but nothing with Opera

hhhmmm? It seems the virus is directly targeting IE, Firefox and Chrome?

again, Art_2010, can you deactivate the link in your first post? (make it hxxp)

lol forgot to mention something important >>> my first test in IE9 generating a file shield alert was done with IE9 sandboxed >>> see my screen shot above with malware detected in the IE temp folder ;D

C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0BU9CEB\top_1286364087[1].js [L] JS:Downloader-AFY [Trj] (0)

Notified WOT: http://www.mywot.com/en/forum/7980-dubizzle-com-rated-green-when-hacks-certain-browsers

Sent Report to Browser Defender.

Confirmed malware, Norman will ad detection for - top_1286364087.js - Processed - JS/Agent.HJ

According to all those experts who lent their time checking this issue it was confirmed that there was a malicious code (malware) embedded on this website on the date that this topic was posted. But as of this writing I didn’t get anymore the same warning that I’d experienced two days ago. If it was fixed or not I don’t know since Dubizzle didn’t issue anything about it?

If indeed it was fixed, we didn’t know when they’d put a stop on it and when they got aware of its occurrence? Dubizzle didn’t post something about the malicious threat probably because of fear of the negative effects of the problem or I just missed the news regarding this?

If they will just go on silent mode and will not admit that their website had been compromised then people who experienced the issue will still have some questions in their minds.

Came across with this Symantec’s article regarding the “Pay Per Install – The New Malware Distribution Network - http://www.symantec.com/connect/blogs/pay-install-new-malware-distribution-network”, I hope this is not the case on some of the popular portals which resorts in this kind of cheap methods in order to gain more profits?

What would you think guys? ???

Hello Folks,

I’m an official representative of Dubizzle.com and I thought I should send a clarification regarding this issue here.

Dubizzle.com is not infected by any Trojan, thus the new Avast definitions update conflicted with the order we loaded our libraries so you may get alerted by Avast when you try to access Dubizzle.com

In the meanwhile, we have updated our code until the conflict is fixed.

Please feel free to report any issue on Dubizzle to support@dubizzle.com

We respond really fast. :slight_smile:

Thank you.