Author Topic: I am confused about an infection being Blocked.  (Read 2547 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I am confused about an infection being Blocked.
« on: January 31, 2017, 04:16:32 AM »
I am using a MacBook Pro with Google Chrome as my browser.

Hello! Here is a little back story. I was watching some of James Veitch's videos on YouTube. (If you don't know who he is, he responds to spam emailers to mess with them and waste their time) Wanting to know more about what he does I Googled his name. The first website Google gave me appeared to be his website. So I clicked on it. What I thought was a Mac notification popped up saying my flash was outdated. Not caring I clicked close or cancel (I don't remember which it said). After nothing happened I realized what it was. I quickly jammed the back arrow as avast notified me of a blocked infection.

Infection: JS:Includer-BOF [TrJ]
URL: (I don't want to link the site for your safety)
File: (gzip)
Proscess: /Applications/Google Chrome.app/Contents/MacOS/Google Chrome

To make sure everything was clean on my Mac I cleared Chrome's cache and cookies. What is confusing me the most is now everytime I Google James Veitch I get an infection blocked notice even thought I don't click on the fake site. (Also something to note I wasn't notified about an infection block while on Google until after I had clicked the link.)

Why does this happen? Is my Google safe to use? Is there a way to fix this?

Any help is appreciated.

I am also running a full system scan to make sure nothing got through.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37601
  • Not a avast user
Re: I am confused about an infection being Blocked.
« Reply #1 on: January 31, 2017, 08:20:54 AM »
Quote
URL: (I don't want to link the site for your safety)
Post the link unclickable   http as hxxp   www as wxw


REDACTED

  • Guest
Re: I am confused about an infection being Blocked.
« Reply #2 on: January 31, 2017, 11:31:22 AM »
Post the link unclickable   http as hxxp   www as wxw

URL: hxxp://veitch.me/

Sorry, didn't think about that.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37601
  • Not a avast user
Re: I am confused about an infection being Blocked.
« Reply #4 on: January 31, 2017, 04:40:38 PM »
HTML scan > URL: hxxp://veitch.me/

https://virustotal.com/en/file/4d0e58f85fcdc102b613dab31bb16a789a0a34328b69010129e7b9d0e2f6821d/analysis/1485877130/




Quote
To make sure everything was clean on my Mac I cleared Chrome's cache and cookies. What is confusing me the most is now everytime I Google James Veitch I get an infection blocked notice even thought I don't click on the fake site. (Also something to note I wasn't notified about an infection block while on Google until after I had clicked the link.)
If this is still a problem you can ask in the Mac forum section, you may give link to this topic






« Last Edit: January 31, 2017, 04:57:14 PM by Pondus »

REDACTED

  • Guest
Re: I am confused about an infection being Blocked.
« Reply #5 on: January 31, 2017, 06:20:23 PM »
I wanted to thank you guys for getting back to me. I ran a system scan on my MacBook and everything came back clean, except 27 files couldn't be scanned but that shouldn't be a problem. I wasn't really expecting to find anything because Avast said it blocked it but wanted to make sure.

As for my Google search problem. It appears to have gone away. I can now search James' name without getting a blocked infection notice. After looking at the virustotal page Pondus linked I am surprised so few antivirus' recognized the threat. I am glad I choose to use Avast.

Thanks again you guys. If I have any other questions or infections I will be back.   :D

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37601
  • Not a avast user
Re: I am confused about an infection being Blocked.
« Reply #6 on: January 31, 2017, 08:28:07 PM »
Quote
After looking at the virustotal page Pondus linked I am surprised so few antivirus' recognized the threat. I am glad I choose to use Avast.
Most malicious files start there life undetected / low detection rate

Avast have always been good at at detecting infected websites. There are many examples here that avast and Sucuri are the first to detect