Avast WEBforum

Other => Viruses and worms => Topic started by: Flopy on March 17, 2008, 07:45:39 PM

Title: Avast and grc.com
Post by: Flopy on March 17, 2008, 07:45:39 PM
Hi,
Thank you for your very good antivirus!!!
I've a problem: if I go to grc.com, avast detect a trojan in the home page!!
The trojan is: http://www.grc.com/iframe.htm\unp195131448 (HTML:RogueIframe [trj])

Is this right???

Thank you
Title: Re: Avast and grc.com
Post by: Lisandro on March 17, 2008, 07:51:33 PM
Please, do not post live links to malware or false positives.
Can you edit the link (adding spaces into its name)? Thanks.

Dr. Web shows www.grc.com as being clean... but I couldn't scan the iframe.htm page itself.
Title: Re: Avast and grc.com
Post by: esingleton on March 17, 2008, 08:35:04 PM
I am getting a similar warning when I visit www.chase.com and after trying www.grc.com.

HTML: RogueIFrame (trj)

I only get the warning on the Windows XP pro machines. The SBS2003 Server and the Vista clients do not get any warning.
Title: Re: Avast and grc.com
Post by: AiNt on March 17, 2008, 08:40:38 PM
I've also experienced the same warning. I tried to open the forum on the grc.com site but I get the same trojan warning again.
Title: Re: Avast and grc.com
Post by: DavidR on March 17, 2008, 08:43:31 PM
The iframe.htm page is called from the iframe tag (see code below) in the grc.com\intro.htm page, I thought that DrWeb was now scanning deeper.

Code: [Select]
<iframe id="zerosize" src="/iframe.htm" scrolling="no"></iframe>
The above doesn't seem very dangerous, however the code in the iframe page, has yet another iframe tag and that calls another page, http :// www . grctech.com/_c5mctohclsuvh_/iframe1.htm. So this circular calling may be suspicious. Note the total content of the called pages is just an iframe tag. To all intents and purposes they appear benign, but I gave up after the 4th page, but I can imagine it goes on for some time. Why is the 64,000 dollar question.

Code: [Select]
<iframe src="http://www.grctech.com/_c5mctohclsuvh_/iframe1.htm" width=0 height=0 frameborder=0 marginwidth=0 marginheight=0 scrolling="no"></iframe>
Which calls yet another page from an iframe tag
Code: [Select]
<iframe src="http://www.grc.com/iframe2.htm" width=0 height=0 frameborder=0 marginwidth=0 marginheight=0 scrolling="no"></iframe>

Which calls yet another page from an iframe tag
Code: [Select]
<iframe src="http://www.grctech.com/_3mg42bcq3evok_/iframe3.htm" width=0 height=0 frameborder=0 marginwidth=0 marginheight=0 scrolling="no"></iframe>
This page call seems to end the cycle as the only code on the called page is:
Code: [Select]
<html></html>
I don't know what is going on but it is strange to say the least, but appears benign.
Title: Re: Avast and grc.com
Post by: tevion on March 17, 2008, 08:52:01 PM

yes i am too getting this warning from avast webshield.
I am used to test sometimes my ports but never before i got this warning.
Tevion


Title: Re: Avast and grc.com
Post by: DavidR on March 17, 2008, 08:59:17 PM
You can still submit a false positive email to virus @ avast . com (without the spaces) and obviously no file to attach. Give the URL and malware name and a link to this topic so they can get more information.
Title: Re: Avast and grc.com
Post by: roundtrip on March 17, 2008, 09:17:57 PM
Same virus alert when visiting:
http://www.autotrader.co.uk
Title: Re: Avast and grc.com
Post by: tevion on March 17, 2008, 09:33:09 PM
You can still submit a false positive email to virus @ avast . com (without the spaces) and obviously no file to attach. Give the URL and malware name and a link to this topic so they can get more information.

thanks DavidR, just done.
Title: Re: Avast and grc.com
Post by: drhayden1 on March 18, 2008, 12:27:45 AM
got the same warning from going to grc.com and never did before......

(http://i27.tinypic.com/mszzgw.gif)



Title: Re: Avast and grc.com
Post by: kubecj on March 18, 2008, 12:36:53 AM
FP. Please update, it should be gone.
Title: Re: Avast and grc.com
Post by: drhayden1 on March 18, 2008, 12:39:26 AM
just did and it's still giving the warning ???

(http://i25.tinypic.com/sqii3n.jpg)
Title: Re: Avast and grc.com
Post by: polonus on March 18, 2008, 12:50:01 AM
Hi Dan,

You heard it from the man, you are vulnerable to a False Positive,

Damian

P.S. Click pic for animation
Title: Re: Avast and grc.com
Post by: drhayden1 on March 18, 2008, 12:53:19 AM
thanks kubecj :)
and isn't that so cute damian 8)

click on box to see my animation ;)
Title: Re: Avast and grc.com
Post by: DavidR on March 18, 2008, 01:02:16 AM
FP. Please update, it should be gone.

No VPS update available, 080317-0 is current and still getting the alerts.
Title: Re: Avast and grc.com
Post by: drhayden1 on March 18, 2008, 01:04:00 AM
 (current version 080317-0) same here davidr my friend ;)
Title: Re: Avast and grc.com
Post by: drhayden1 on March 18, 2008, 02:09:04 AM
(current version 080318-0) and going to grc.com is fine now...thank you!!
Title: Re: Avast and grc.com
Post by: esingleton on March 18, 2008, 03:23:17 AM
Both Chase and GRC.com are fine for us aswell, Thanks!