Author Topic: False Positive on WebShield?  (Read 3020 times)

0 Members and 1 Guest are viewing this topic.

Cafeen

  • Guest
False Positive on WebShield?
« on: June 16, 2012, 02:37:43 AM »
Myself, and several other users of the site:
wxw.disboards.com

are experiencing Avast blocking this site for an HTML:Script-inf infection ([site]/|{gzip} is listed as URL)

I ran it through the 4 of the 5 tools in !Donvan's signature (urlQuery, urlVoid, Zulu risk analyzer, and Sucuri SiteCheck, the Wepawet was erroring out with DB connection failures) and they all come back clean. There has been no word of anything hinky from the site owners (of which, I am not one, just a user).

Is there any other action that I should, or even can take? Since I have no affiliation with the site, this is about as much info as I can gather.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False Positive on WebShield?
« Reply #1 on: June 16, 2012, 05:36:23 AM »
I ran it through the 4 of the 5 tools in !Donvan's signature (urlQuery, urlVoid, Zulu risk analyzer, and Sucuri SiteCheck, the Wepawet was erroring out with DB connection failures) and they all come back clean. There has been no word of anything hinky from the site owners (of which, I am not one, just a user).

Is there any other action that I should, or even can take? Since I have no affiliation with the site, this is about as much info as I can gather.

You can report a possible FP here: http://www.avast.com/contact-form.php?loadStyles
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: False Positive on WebShield?
« Reply #2 on: June 16, 2012, 03:37:26 PM »
Hi Cafeen,

The discussion of disboards in-depth can be found here:
http://forum.avast.com/index.php?topic=99727.0

Also see:
http://forum.avast.com/index.php?topic=99733.0


Both True Indian, Polonus, and I find the partner site safe-surf suspicious.


~!Donovan
« Last Edit: June 16, 2012, 03:47:26 PM by !Donovan »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: False Positive on WebShield?
« Reply #3 on: June 16, 2012, 03:39:22 PM »
Hi Asyn,

Our friend, !Donovan, is right here.
It might be possible that the heavily obfuscated script was being flagged: wXw.safesurf-check.com/gate.php (related to Zeus trojan)
vulnerability for fx browsers, avast webshield flags as HTML:Script-inf...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2295
Re: False Positive on WebShield?
« Reply #4 on: June 16, 2012, 03:44:07 PM »
Hi Asyn,

Our friend, !Donovan, is right here.
It might be possible that the heavily obfuscated script was being flagged: wXw.safesurf-check.com/gate.php (related to Zeus trojan)
vulnerability for fx browsers, avast webshield flags as HTML:Script-inf...

polonus
Hello,
yes, avast! detect there script tag which goes to "safesurf-check.com".

Milos

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False Positive on WebShield?
« Reply #5 on: June 16, 2012, 05:42:49 PM »
Hi Asyn,
Our friend, !Donovan, is right here.
It might be possible that the heavily obfuscated script was being flagged: wXw.safesurf-check.com/gate.php (related to Zeus trojan) vulnerability for fx browsers, avast webshield flags as HTML:Script-inf...
polonus

Hi D.,
good that you guys checked it. :) (I didn't, as I was low on time in the morning...)
Also thanks to Milos for the confirmation.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0