


Opendns updater and avast 2016 update#
I am on the ESR update channel, but someone else said the update seems to have worked (firefox v60.0.02 ). Thanks for sharing your thoughts! AVG updated today 6-7 and I cleaned all cache ect. Wouldn't expect anything until morning unless a blue happens to pay attention and wants to respond even though there may be nothing that he/she can do (guessing tech staff is also M-F 9-5)Īddendum: read more closely all the posts and appears in this thread Avast is also involved. Highly doubtful that anything terrible is happening if nothing else out of the hundreds of AV/malware suites is finding anything.Īddendum: read more closely all the posts and appears in this thread Avast is also support here pretty much operates on Pacific Time business hours. In general, I don't think anyone should panic. (I have got to get some listings done, but this is another good procrastination opportunity Guess I'll take a look and see if I can figure anything out. Have not seen that script actually called in my eBay travels, but wouldn't anyway unless I did get redirected or trojaned (no AV running to throw warnings and no other manually set traps set).
Opendns updater and avast 2016 code#
I'm not good enough with JavaScript debugging to walk through it in a debugger and figure out what it's doing (and that may be why the Firebug thing in the code - that may be built in code to detect debugging attempts and thwart them), but may take a stab at it.ĭon't know at this point. The only way to decipher it is to be really good with JavaScript coding and debugging, or to run it and look for results of some variety (good or bad).Īny legitimate eBay code shouldn't look like that though IMO. It's what looks like over a thousand (short) lines of pretty much totally obfuscated JavaScript, with what looks like some calls to launch Java application(s) (downloaders?), something referencing FIrebug in Firefox (old standalone version of what is now built in webdeveloper tools in Firefox), and the rest is a horrible mess of obfuscated function calls, url encoded strings, and basically unreadable and indecipherable. However, I just took a look at /rdr/js/s/ and now I'm not so sure. I posted a general response on the PS board (I believe) earlier, indicating that evidence so far made it appear it was just another AVG (and Avast?) false positive detection, that that js file was not found to contain anything malicious by any online resources I checked it with, the fact that it IS only AVG (and Avast?) flagging it (neither of which I put much faith in), leads me to believe it is a false positive again this time. Wouldn't expect anything until morning unless a blue happens to pay attention and wants to respond even though there may be nothing that he/she can do (guessing tech staff is also M-F 9-5) EBay support here pretty much operates on Pacific Time business hours.
