Help pls. Adguard Bug or smth.

Status
Not open for further replies.

Rengar

Level 17
Thread author
Verified
Top Poster
Well-known
Jan 6, 2017
835
Half an hour Adguard pops up with this message. What do i do?
 

Attachments

  • Screenshot_1.png
    Screenshot_1.png
    13 KB · Views: 436

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,821
Is the block only popping up on a certain site? If so the site could be compromised; probably some malicious iframe redirecting to the blocked site.
If it's popping up constantly on all sites (or even when your browser's isn't open) I suggest firing up some second opinion scanners and seeing if they pick up anything.
 

Rengar

Level 17
Thread author
Verified
Top Poster
Well-known
Jan 6, 2017
835
Is the block only popping up on a certain site? If so the site could be compromised; probably some malicious iframe redirecting to the blocked site.
If it's popping up constantly on all sites (or even when your browser's isn't open) I suggest firing up some second opinion scanners and seeing if they pick up anything.
See the picture. Only that site.
 
D

Deleted member 65228

WebAssembly is basically a new programming language (it would appear) which is closer to Assembly but also supports C and C++ which can be used on the web, you can read more about it here: WebAssembly & WebAssembly

I've never used it nor seen malware use it so I cannot provide much assistance past that. Which is a shame really. If it is used for malware somehow then that would be quite smart since it'd be unexpected and out of normal scan radars I'd imagine

If the block request was from browsing then I wouldn't worry about it, although if another running program was responsible (if you know) and you weren't browsing at the time, then I'd do a checkup of the system.
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,458
Quote : " We notice some functions that come straight from the Coinhive documentation, such as .hasWASMSupport(), which checks whether the browser supports WebAssembly, a newer format that allows users to take full advantage of the hardware’s capability directly from the browser. If it doesn’t, it would revert to the slower JavaScript version (asm.js). "

Source : Persistent drive-by cryptomining coming to a browser near you - Malwarebytes Labs

If I understand this correct it looks like Coinhiver actually use it if available.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top