Trojan-Downloader.JS.LuckySploit.l

Taffycat

Crunchy Cat
Joined
Jun 1, 2006
Messages
12,581
Reaction score
1,055
I went to a website I regularly visit (for graphics) earlier today, and it caused Kaspersky to let out a scream. It had detected a Trojan called "Trojan-Downloader.JS.LuckySploit.l" which it blocked. But do you mind if I just confirm with you that it did successfully block it please? Trusting soul that I am, ;)

When I did a complete scan, it showed up as "Threats have been detected!" but it was zapped, according to the screen snips, right guys? It's just that having been virus-free pretty much forever, I want to be certain I'm interpreting KIS correctly. I know...Duh. :D

Thank you for looking, I appreciate it.


Virusalert1.jpg


Virusalert2.jpg
 
Joined
Feb 16, 2009
Messages
2,123
Reaction score
18
Hi,

I reckon youre sorted cos of the little box thats ticked for stuff disinfected.KIS isgood i think but keep an eye on it.....ciao....sounds like miaow LOL
:) Zzzzz
 

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
Yep, KIS detected the trojan and prevented access when you visited that webpage. :thumb: I've had similar things happen on legit websites, which I can only assume have been injected with rogue code :(
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
... a website ... for graphics ...


can you PM me the site address ;)

KIS says it "blocked" it, it was blocked. :thumb:



:user:
 

Taffycat

Crunchy Cat
Joined
Jun 1, 2006
Messages
12,581
Reaction score
1,055
Oh Great, thank you guys, I know I was fussing, but just wanted to be entirely sure :D

Sure thing Mucks, will do :nod:
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
The "trojan" appears to be a cleverly written javascript code and being injected via an ad ... :rolleyes:

I'll email the host. :thumb:
 

Taffycat

Crunchy Cat
Joined
Jun 1, 2006
Messages
12,581
Reaction score
1,055
:eek: That sounds very sneaky. Would I be correct in thinking that you don't even need to click the ad to get into trouble? I always make a point of never deliberately clicking ads.

Thank you for emailing the host - it would be a pity if this site was compromised, because it's one of the best (for this kind of graphics resource). :thumb:
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
Yes, sad to say, you are correct ... it's quite cleverly written. :rolleyes:

It is a newish variant, and, if you wanna test out your AV program, still available from the source. ;)



:user:
 

Taffycat

Crunchy Cat
Joined
Jun 1, 2006
Messages
12,581
Reaction score
1,055
Yikes, KIS remained quiet when I visited the site to "check" a while ago.... so I'm running scans at the minute.
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
Taffycat said:
Yikes, KIS remained quiet when I visited the site to "check" a while ago.... so I'm running scans at the minute.
Oh, don't worry, it no longer being injected as far as I can see. :thumb:

The ad is probably on a cycle, may never see it again or you'd have to be there at the right time.

Oh, ang on ... that site aint the source. ;)
 
Joined
Apr 11, 2007
Messages
956
Reaction score
59
My wife has a laptop, and for the last few nights she has been getting a "Personal Antivirus" program comming up as soon as she boots up to the work bench. This is showing her that she has a Trojan on board among other infections.She did not ask for his prog` it just appeard.She has a antivirus program that came with the laptop,its called "Norton Antivirus" On scanning using Norton it shows that all is well. Could this unknown antivirus prog` be a virus in it self? Because to get rid of all those bugs you have to pay,giving your credit card details.But how do we get rid of it.

historian :confused:
 
Joined
Apr 19, 2008
Messages
4,081
Reaction score
1
historian said:
My wife has a laptop, and for the last few nights she has been getting a "Personal Antivirus" program comming up as soon as she boots up to the work bench. This is showing her that she has a Trojan on board among other infections.She did not ask for his prog` it just appeard.She has a antivirus program that came with the laptop,its called "Norton Antivirus" On scanning using Norton it shows that all is well. Could this unknown antivirus prog` be a virus in it self? Because to get rid of all those bugs you have to pay,giving your credit card details.But how do we get rid of it.

historian :confused:


It sure sounds like a virus Historian..

Ok here goes...

Goto Trend Micro Housecall and run that and see oif it pics anything up..

Then download and instal Super anti Spyware

Then downlad and instal Malwarebyte Free

Boot your computer as normal and run House call and see if it pics up anything...
Then restart the computer in "Safe Mode" and disconect it from the internet and run the later two programs and see what happens...If there is any sort of virus or trojan or spyware one of these is going to pick it up....If anything is picked up and the progs donb't sort it out let us know what has been detected and we can take it from there...
 
Joined
Apr 11, 2007
Messages
956
Reaction score
59
Madxgraphics said:
It sure sounds like a virus Historian..

Ok here goes...

Goto Trend Micro Housecall and run that and see oif it pics anything up..

Then download and instal Super anti Spyware

Then downlad and instal Malwarebyte Free

Boot your computer as normal and run House call and see if it pics up anything...
Then restart the computer in "Safe Mode" and disconect it from the internet and run the later two programs and see what happens...If there is any sort of virus or trojan or spyware one of these is going to pick it up....If anything is picked up and the progs donb't sort it out let us know what has been detected and we can take it from there...

Hello Megxgraphics.
Many thanks for your reply.
My wife did down load Trend Micro Housecall program but could not run it,it would appear that the suspect antivirus prog` is blocking it.
Is that possible? She has now disconected from the internet.
historian.

 
Last edited:
Joined
Apr 11, 2007
Messages
956
Reaction score
59
Madxgraphics said:
It sure sounds like a virus Historian..

Ok here goes...

Goto Trend Micro Housecall and run that and see oif it pics anything up..

Then download and instal Super anti Spyware

Then downlad and instal Malwarebyte Free

Boot your computer as normal and run House call and see if it pics up anything...
Then restart the computer in "Safe Mode" and disconect it from the internet and run the later two programs and see what happens...If there is any sort of virus or trojan or spyware one of these is going to pick it up....If anything is picked up and the progs donb't sort it out let us know what has been detected and we can take it from there...
Hello Maxgraphics.
Thanks for your reply.

My wife did down Trend Micro housecall program but couldn`t run it. It would appear that the suspect antivirus program is blocking it,is that possible?
She has since unplugged her lap top from the internet.
historian.
 
Joined
Feb 16, 2009
Messages
2,123
Reaction score
18
Check this linky for some info.... http://www.scambusters.org/fakeantivirus.html

Also trust nothing....even this link. I think its okay but you do need to be very careful....i had a fake virus jobby last year and it took forever to dump it....i wasnt joking about trust as many will agree...trust nothing. Scan everything.
Hope this link was some help.
Zzzzz
 
Joined
Apr 11, 2007
Messages
956
Reaction score
59
captain zed said:
Check this linky for some info.... http://www.scambusters.org/fakeantivirus.html

Also trust nothing....even this link. I think its okay but you do need to be very careful....i had a fake virus jobby last year and it took forever to dump it....i wasnt joking about trust as many will agree...trust nothing. Scan everything.
Hope this link was some help.
Zzzzz

Hi Captain Zed.
Thanks for your reply.
I got onto the web site you mentioned,and I subscribed to their news letter.
Then I got another page come up and it was for a sales pitch to buy a book.I scrolled down the very long page,looking for a exit or close button but couldn`t see one so I closed it down.
historian.
 
Joined
Feb 16, 2009
Messages
2,123
Reaction score
18
I'll try that site again and see what happens....alsoproves that you cant be too careful ,man.
 
Joined
Feb 16, 2009
Messages
2,123
Reaction score
18
Hi Historian,

Had a good nose about that site and nothing untoward happened to me....actually went looking for stuff tohappen and no luck, good or bad.
Not a great site either looking back. Just it had thta info about fake viruses.
Zzzzz
 
Joined
Apr 11, 2007
Messages
956
Reaction score
59
Madxgraphics said:
It sure sounds like a virus Historian..

Ok here goes...

Goto Trend Micro Housecall and run that and see oif it pics anything up..

Then download and instal Super anti Spyware

Then downlad and instal Malwarebyte Free

Boot your computer as normal and run House call and see if it pics up anything...
Then restart the computer in "Safe Mode" and disconect it from the internet and run the later two programs and see what happens...If there is any sort of virus or trojan or spyware one of these is going to pick it up....If anything is picked up and the progs donb't sort it out let us know what has been detected and we can take it from there...

Hi Madxgraphics.
Just to let you know what progress we have made re:virus.
I down loaded "SuperAntiSpywere" onto my wifes laptop and it
would appear that that virus is no longer with us.Many thanks.
But I really should have thought of it first because I have it on my computer.
I promise to do better.:blush:
historian
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top