Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 43035
  • Total Topics: 16219
  • Online Today: 6022
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: wtf: many advertisements in chrome (YouTube) but no AV finding virus  (Read 17370 times)

0 Members and 5 Guests are viewing this topic.

jheysen

  • SCF Global Moderator
  • *****
  • Posts: 879
  • KARMA: 121
  • Gender: Male
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #10 on: 01. September 2014., 03:07:36 »
You should not see the colors, but see wether the processes are Digitally Signed (You can check that with Process explorer) and begin to check wich DLLs are hooked to the browsers...
The other attack vector is going with ProcessMonitor... but you should have an idea of what are you looking for before opening it

Samker's Computer Forum - SCforum.info

Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #10 on: 01. September 2014., 03:07:36 »

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #11 on: 01. September 2014., 03:07:42 »
Sophos Virus Removal tool cannot install (in safe mode): no network location found.

Strange error :s

Gonna reboot and give up I suppose? Two full new installations... Will take me well over a week! :(

Devvie
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #12 on: 01. September 2014., 03:15:57 »
You should not see the colors, but see wether the processes are Digitally Signed (You can check that with Process explorer) and begin to check wich DLLs are hooked to the browsers...
The other attack vector is going with ProcessMonitor... but you should have an idea of what are you looking for before opening it

I understand I should not look for colors ;p It was one of the two proceses that didn't made immediate sense :)

I looked with your comments in mind, but still looks good to me?



http://i.imgur.com/L9bBdBM.png
That said, I should really clean chrome.exe shortcuts and stuff... I do not like the yellow pop-up for chrome... Does not make a lot of sense, unless hi-jacked in the simplest way possible... Shortcut modification. And yes, I did not test for that :) Cleaned %AppData% for chrome, not shortcuts. Still, IE is not good either!

We'll test and see :)

Devvie
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

jheysen

  • SCF Global Moderator
  • *****
  • Posts: 879
  • KARMA: 121
  • Gender: Male
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #13 on: 01. September 2014., 03:49:52 »
There's a strange call to explorer.exe
And maybe you can throw into action ProcessMonitor filtering just for chrome.
Did you check the usual hooks for explorer and WinLogon?

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #14 on: 01. September 2014., 12:40:26 »
There's a strange call to explorer.exe
And maybe you can throw into action ProcessMonitor filtering just for chrome.
Did you check the usual hooks for explorer and WinLogon?

Oh F* me! You are right! How could I not see this... I'm not as much an expert as I thought, lol.

I guess I need your help now... How to proceed next?
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

Samker's Computer Forum - SCforum.info

Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #14 on: 01. September 2014., 12:40:26 »

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #15 on: 01. September 2014., 16:18:58 »
Sophos and 360 Total Security on high still returned clean scans.

I must say, I really like 360 Total Security. You should check it out, might replace my avast real soon! ;p

Really need some advice on that explorer hi-jack you uncovered... https://encrypted.google.com/search?rlz=1C1GPCK_enNL430NL430&{google:acceptedSuggestion}oq=goo&sourceid=chrome&ie=UTF-8&q=google#q=C%3A%5CWindows%5Cexplorer.exe+%2Ffactory%2C%7Bceff45ee-c862-41de-aee2-a022c81eda92%7D+-Embedding



Did I mention PC1 is Windows 7 Enterprise...? Might this explain the hi-jack?

Devvie
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

neerajrawat1

  • SCF VIP Member
  • *****
  • Posts: 234
  • KARMA: 36
  • Gender: Male
  • We believe in sharing is caring
    • Experts Galaxy
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #16 on: 01. September 2014., 19:59:42 »
Did you try Emsisoft and malwarebytes as well?

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #17 on: 01. September 2014., 21:42:08 »
Did you try Emsisoft and malwarebytes as well?
Yes, everything in the list has been installed / ran... To no avail! :(

I mean: YOU guys do not have an advertisement square banner above suggested titles in youtube when watching videos, right? I really think they should not be there, but... Starting to doubt myself now :(



Devvie
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #18 on: 01. September 2014., 21:43:37 »

Did you check the usual hooks for explorer and WinLogon?
Shouldn't any decent AV detect this stuff...?
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

neerajrawat1

  • SCF VIP Member
  • *****
  • Posts: 234
  • KARMA: 36
  • Gender: Male
  • We believe in sharing is caring
    • Experts Galaxy
Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #19 on: 01. September 2014., 22:00:36 »
No idea what are you referring to? I am using Adblock Plus, try it, may help.

Samker's Computer Forum - SCforum.info

Re: wtf: many advertisements in chrome (YouTube) but no AV finding virus
« Reply #19 on: 01. September 2014., 22:00:36 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising