Author Topic: Another Query of Trojan Horse or False Positive??  (Read 3864 times)

0 Members and 1 Guest are viewing this topic.

avast fan

  • Guest
Another Query of Trojan Horse or False Positive??
« on: April 14, 2010, 05:01:33 PM »
Hi im using windows 7 x86 and have avast pro av buid 5.0.504 av update 10014-0 and when i visited this wxw.thehipzone.co.uk/high-definition-wii-18 Avasts web shield blocked the site saying it had detected a Trojan Horse? Anyone else can support this? Please note ive broke the link with wxw instead of www.

psw

  • Guest
Re: Another Query of Trojan Horse or False Positive??
« Reply #1 on: April 14, 2010, 05:20:59 PM »
What kind of support do you need? Page from the site really contains malicious script located betwwed tags </head> and <body>.

avast fan

  • Guest
Re: Another Query of Trojan Horse or False Positive??
« Reply #2 on: April 14, 2010, 05:31:57 PM »
Just wanted confirmation that its really a virus rather than a false positive what with me using build 504 of avast that is all.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Another Query of Trojan Horse or False Positive??
« Reply #3 on: April 14, 2010, 05:52:08 PM »
It isn't just that page, the site home page also, so it appears that the site has been hacked and this obfuscated javascript script tag inserted in many pages (if not all) including the favicon.ico file that browser will try to load when they open a page.

See http://www.virustotal.com/analisis/1a56e3ba571a168607ae5034f7f5e2736e07239ed6db7c5e048c308d0a63a574-1271259725, this shows avast isn't alone in finding this page infected.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

avast fan

  • Guest
Re: Another Query of Trojan Horse or False Positive??
« Reply #4 on: April 14, 2010, 07:28:03 PM »
Yes thanks for that info DavidR, Very much appreciated :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Another Query of Trojan Horse or False Positive??
« Reply #5 on: April 14, 2010, 08:11:03 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: Another Query of Trojan Horse or False Positive??
« Reply #6 on: April 14, 2010, 08:20:29 PM »
Hi avast fan,

Site sure has a trojan, half of the scanners there flag it, re:
http://scanner.novirusthanks.org/analysis/a3502edc2f244862d9e543359676b0ef/aW5kZXg=/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!