Strange Javascript/? Malware Problem

If it doesn't fit elsewhere, it goes here
Post Reply
charlestek
Posts: 2
Joined: Wed Feb 26, 2014 7:31 pm

Strange Javascript/? Malware Problem

Post by charlestek » Wed Dec 10, 2014 1:46 pm

I started having problems on my desktop machine last night when ebay filters would not work as well as links on pages that used javascript, probably both locally and for javascript ajax calls.
Today I discovered that all javascript functionality in all browsers (chrome, IE, opera, firefox) was not working.

On this machine I am running Win 7 Ultimate, MalwareBytes premium and Kaspersky antivirus, plus EMET and something called hitmanpro.alert and cryptoprevent.

I then booted my laptop which was last used weeks ago, and found to my surprise that I have the same symptoms on the laptop which is running Win8.1 Pro
The laptop has Webroot SecureAnywhere, MBAM and crytoprevent, emet and hitmanpro.alert.

I just uninstalled MBAM on the desktop which did not help. Tried disabling Kaspersky, no luck. Tried uninstalling EMET, no effect

I did find that if I run say firefox in Sandboxie, javascript does work. Can anyone tell me what is unique to Sandboxie that might help me identify what is disabling javascript in both machines.
I can only guess that this may be malware, but neither AV which are different in both machines plus MalwareBytes has detected anything.

charlestek
Posts: 2
Joined: Wed Feb 26, 2014 7:31 pm

Re: Strange Javascript/? Malware Problem

Post by charlestek » Wed Dec 10, 2014 9:55 pm

I found the problem which is DD-WRT's fault. A few days ago, I had to go into DD-WRT setup and I remember going to the security tab and remember seeing the "Additional Filters" with its "Filter Java Applets". I said to myself, hey that's great, even though I have removed java on all my machines. So I checked the checkbox.

Well, guess what, the moronic DD-WRT developers do not know that Java is not the same as javascript, as I found out when I displayed the help menu on the DD-WRT gui webage :
Help says: "Filter Java Applets - Blocks HTTP requests containing a URL ending in ".js" or ".class"

"Filter Java Applets" therefore would block any non inline javascript being downloaded for a page get or post, and probably would block any Json javascript ajax requests.

I guess I need to write a post on the DD-WRT forum.....

Why sandboxie managed to sneak the http calls through is a mystery.......
But I'm thinking maybe since I hadn't blown away the sandbox it maybe contained say JQuery library scripts and any other scripts the page needed without fetching them from the host .

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest