Author Topic: Possible false positive?  (Read 22844 times)

0 Members and 1 Guest are viewing this topic.

Edward12345

  • Guest
Re: Possible false positive?
« Reply #15 on: March 29, 2014, 03:52:51 AM »
Same issue with xhamster.com

Hectic4409

  • Guest
Re: Possible false positive?
« Reply #16 on: March 29, 2014, 04:11:27 AM »
Getting the same thing on .....      ftop.ru   .............a site that I have also had booked marked for quite some time and just used the other night.

It is showing the
 
URL as....h_www_ftop_ru__|{gzip}
and the
Infection as ...JS:Includer-BAO [Trj]

I have NEVER had this pop up until tonight
« Last Edit: March 29, 2014, 04:24:19 AM by Hectic4409 »

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: Possible false positive?
« Reply #17 on: March 29, 2014, 04:31:29 AM »
Same issue with xhamster.com

detection seems correct



the site was part of the distribution network of malware
level of severity 3

ET RBN Known Russian Business Network IP group 352

http://urlquery.net/report.php?id=1396062571875

Zulu scaler report suspicious files

http://zulu.zscaler.com/seen/53144f39e00f8d523042bf84dc6d5f7e-1395355893

AVG reports have found 4 threats
http://www.avgthreatlabs.com/website-safety-reports/domain/xhamster.com/
 

hidden iframe





 evaluation  and obfuscated

http://wepawet.iseclab.org/view.php?hash=27f3653318d17014d6e4a2a0e3cfa767&t=1396063631&type=js

site listed blacklist
https://www.virustotal.com/en/url/bfdb91ff433083f7223ddb06a26c2b6bb0e32c7c502bee21a6af5dcc30e83a36/analysis/1396062364/

cysc.blacklisted.gen
http://support.clean-mx.de/clean-mx/viruses.php
« Last Edit: March 29, 2014, 04:19:27 PM by jefferson santiag »

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: Possible false positive?
« Reply #18 on: March 29, 2014, 04:53:13 AM »
URL as....h_www_ftop_ru__|{gzip}
and the
Infection as ...JS:Includer-BAO [Trj]

I have NEVER had this pop up until tonight

This site contains malicious redirects
and also the  detection seems correct




1: hxxpservice.clicksvenue.com / show.php sid = 104 & spid = 169 & scid = 10 & cgid = 2 -> hxx / xxw.ftop.ru/1/2.html?

http://wepawet.iseclab.org/view.php?hash=730e3927044f4fd303ba9a00dc0ba56c&t=1396064425&type=js

unknown_html
http://support.clean-mx.de/clean-mx/viruses.php

hidden iframe



« Last Edit: March 29, 2014, 04:19:53 PM by jefferson santiag »

Yawty

  • Guest
Re: Possible false positive?
« Reply #19 on: March 29, 2014, 06:48:20 AM »
I thought I was the only one having this sudden problem but it would appear that a majority of "Adult websites" are infected by
 "JS:Includer-BAO [Trj]"

Are there any quick ways to fix this problem manually?
Or is it until the said sites are clean again from infection

but i find it weird that i have this problem with my personal computer but i can still access these sites normally when im using a public computer


PinkiePie

  • Guest
Re: Possible false positive?
« Reply #20 on: March 29, 2014, 06:55:31 AM »
Oh! I'm happy that I'm not the only one running into this. I hope it gets solved, it is also coming from an adult website in my experience.

Offline chris..

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2933
Re: Possible false positive?
« Reply #21 on: March 29, 2014, 08:18:08 AM »
Hello,

same "JS:Includer-BAO [Trj]" with some others webpage since 140328-1 vps
« Last Edit: March 29, 2014, 10:45:14 AM by chris05 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Possible false positive?
« Reply #22 on: March 29, 2014, 09:57:44 AM »
Norman lab confirms infection..... and added detection

Quote
Files:  wxw.heaven666.org.htm: Includer.A


Yawty

  • Guest
Re: Possible false positive?
« Reply #23 on: March 29, 2014, 10:24:41 AM »
So will this be fixed? or the sites infected are forever in limbo?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Possible false positive?
« Reply #24 on: March 29, 2014, 10:49:16 AM »
So will this be fixed? or the sites infected are forever in limbo?
or fix website    http://forum.avast.com/index.php?topic=148216.0   /   http://forum.avast.com/index.php?topic=148215.0


Offline Flippy

  • Avast team
  • Jr. Member
  • *
  • Posts: 45
Re: Possible false positive?
« Reply #25 on: March 29, 2014, 04:11:25 PM »
Hello,

sorry detection JS:Includer-BAO caused some false positives and its switched off. Sorry for any inconvenience.

Best regards,

Filip Chytrý
Virus analyst

Hectic4409

  • Guest
Re: Possible false positive?
« Reply #26 on: March 30, 2014, 07:27:29 AM »
I thank you and my wife thanks you. She was kind of upset that she could not visit some of her "favorite" sites as well ;)