Avast WEBforum

Other => Viruses and worms => Topic started by: unelluri on March 11, 2011, 05:40:38 PM

Title: False +ve on http://webmail.juno.com
Post by: unelluri on March 11, 2011, 05:40:38 PM
We have false +ve with Latest Avast and signatures from March 11th 3:23 AM (version 110311-0). Blocking http://webmail.juno.com as Trojan HTML:RedirMe-Inf[Trj]. How can I get this removed?
Title: Re: False +ve on http://webmail.juno.com
Post by: romigj on March 11, 2011, 05:44:34 PM
I've been fighting the same thing today, as have 5 other Juno people I know across the country. I've talked to Juno & they haven't had issues/complaints from anyone other than Avast users today.
I haven't gotten anything useful from avast. Then again, I can't check my email.....
Title: Re: False +ve on http://webmail.juno.com
Post by: Pondus on March 11, 2011, 05:49:30 PM
can you post a screenshot of the avast pop-up
Title: Re: False +ve on http://webmail.juno.com
Post by: unelluri on March 11, 2011, 06:00:54 PM
Attached. If I stop Network Shield and Web Shield it stops.

And I am employee of Juno. Juno is one of the leading provider of internet services. By blocking this, avast is causing issue for many of our members. Please let me know, how do I get this fixed, if you know.
Title: Re: False +ve on http://webmail.juno.com
Post by: Pondus on March 11, 2011, 06:07:06 PM
Quote
Please let me know, how do I get this fixed, if you know.
well avast is watching the forum so if this is an FP then i guess they are working on it and it will be fixed soon

Scanned the website with Sucuri / Unmaskparasites / wepawet / virustotal / URLvoid and they all say clean
Title: Re: False +ve on http://webmail.juno.com
Post by: nmb on March 11, 2011, 06:11:56 PM
Please use this contact form: http://www.avast.com/contact-form.php?loadStyles (from the subject drop down, select false postive on website) to notify avast so that they will fix it. You could also put the link to this topic so that they can post here if they need anything or to notify about it.
Title: Re: False +ve on http://webmail.juno.com
Post by: nmb on March 11, 2011, 06:38:54 PM
I guess it is fixed now. I have opened the site on both firefox and ie and it works fine. vps 110311-0
Title: Re: False +ve on http://webmail.juno.com
Post by: jkeenley on March 11, 2011, 06:46:29 PM
I just checked (12:44 pm EST) and it's still blocking me...
Title: Re: False +ve on http://webmail.juno.com
Post by: unelluri on March 11, 2011, 06:48:05 PM
It is not totally. Internal pages are blocked now. Attaching new screenshot.
Title: Re: False +ve on http://webmail.juno.com
Post by: nmb on March 11, 2011, 06:49:51 PM
I just checked (12:44 pm EST) and it's still blocking me...

See pic
Title: Re: False +ve on http://webmail.juno.com
Post by: nmb on March 11, 2011, 06:51:02 PM
It is not totally. Internal pages are blocked now. Attaching new screenshot.

Are you getting it after you have logged into juno?
Title: Re: False +ve on http://webmail.juno.com
Post by: jkeenley on March 11, 2011, 06:55:24 PM
Yes, and with bot ie and firefox.
Title: Re: False +ve on http://webmail.juno.com
Post by: unelluri on March 11, 2011, 06:56:16 PM
yes, after logging in.
Title: Re: False +ve on http://webmail.juno.com
Post by: nmb on March 11, 2011, 06:56:36 PM
Yes, and with bot ie and firefox.
Well then that is the difference. I dont have a account there to test it. Will have to wait for avast.
Title: Re: False +ve on http://webmail.juno.com
Post by: jsh1 on March 11, 2011, 06:58:24 PM
I'm having the same problem with AVAST indicating a TROJAN at the JUNO web-mail login page and not allowing me to go any further with JUNO.  So, now I have lost my JUNO e-mail account access.  Is there any resolution yet?
Title: Re: False +ve on http://webmail.juno.com
Post by: jmatus on March 11, 2011, 07:23:35 PM
Helping a friend with her juno access. She is also getting the HTML:redirME-inf[trj error msg from avast. when logging into webmail.juno.com. When I try to log into her account from my pc, I get the same result.

However, I signed up for a new juno id myself and I had no problem signing on. And from her pc, she was able to sign on to my new juno account successfully, but when she tried her juno id, she got the HTML:redirME-inf[trj error message again.

Not sure what's going on. But maybe the above helps isolate the issue.

jmatus
Title: Re: False +ve on http://webmail.juno.com
Post by: Krouton Kruncher on March 11, 2011, 08:17:08 PM
Avast just released a new definition database (110311-1 from 110311-0)that has cleared the problem up for me.
Title: Re: False +ve on http://webmail.juno.com
Post by: brywalker on March 11, 2011, 08:19:16 PM
Avast has blocked my juno webmail access for the last 5 hours and it is still blocking it.
I dont often run the juno app for access any more but I am running it now and that is working fine. If you have the app its a way around this problem.
I can go to juno.com but when I try to go to my email from there or if I go directly to my bookmark for juno webmail avast blocks it with the malicious url notification,
I have also seen a trojan horse notification,
Juno webmail was working fine last night. Apparently, Avast mistakenly put juno  webmail on the malicious list with its latest definitions.
It seems to me that a lot of people are having this problem and Avast should be a lot faster about getting it fixed.
Title: Re: False +ve on http://webmail.juno.com
Post by: jkeenley on March 11, 2011, 08:21:31 PM
I ran the update, and it now works for me as well. Many thanks o everyone who offered help!
Title: Re: False +ve on http://webmail.juno.com
Post by: brywalker on March 11, 2011, 08:24:59 PM
Works for me too!  Great!!!
Title: Re: False +ve on http://webmail.juno.com
Post by: ckdurbin on March 11, 2011, 08:35:23 PM
Is it a manual update or should it run automatically?
Title: Re: False +ve on http://webmail.juno.com
Post by: news on March 11, 2011, 09:21:15 PM
Try updating manually ckdurbin. Aferwards you should be ok.
Title: Re: False +ve on http://webmail.juno.com
Post by: ckdurbin on March 12, 2011, 01:03:08 AM
Update for me was automatic. Fixed.