Author Topic: safe website but I am getting Trojan Horse Blocked HTML framer-inf (Trj)  (Read 8945 times)

0 Members and 1 Guest are viewing this topic.

mrmillersr

  • Guest
Up until a few days ago I was going to http://aqmthai.com to check the pollution levels here in Thailand with no problem and all of a sudden I keep getting "Trojan Horse Blocked - HTML framer-inf Trj which must be a false positive.  Can someone please help me with a solution on this.  Thank you.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
can you attach a screenshot of the avast warning?

zulu analyser
http://zulu.zscaler.com/submission/show/4771e6f734518f69ad4117cf116726ac-1364881353
« Last Edit: April 02, 2013, 07:45:28 AM by Pondus »

mrmillersr

  • Guest
Attached gif screenshot

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
comes up clean here.   http://sitecheck.sucuri.net/results/aqmthai.com/agishortreport_new.php

you can report possible false positive here.  http://www.avast.com/contact-form.php   change subject to suite your case
you may want to add a link to this topic in case they reply here
 

mrmillersr

  • Guest
So what should I do as reporting it doesn't solve the problem.  Do I need to shut down Avast when I go to that website, but that would leave the computer unprotected.

What if I delete the program and reinstall it.  Will that work?

Or maybe I should just delete Avast and get another anti-virus program.

Need some direction on what to do next.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
when you report it, avast will fix the detection.....if it is wrong.  ;)     if correct, then avast saved your comp

avast is usually correct in these detections and often the first one to detect website infections

no website is 100% secure, the bad guys fish in the pond that has most fish, so if this is a site with many users then it is of course of interest to hack

report it and see if avast reply here..... OBS and dont expect a reply after 5 minutes.  ;)




Offline Flippy

  • Avast team
  • Jr. Member
  • *
  • Posts: 45
Hello folks,

we checked a detection and it was false positive. It should be fixed in next update.Sorry for any inconvenience.

We block that page because of this pdf - northhaze20130327.pdf which is gone now.

Thank you & best regards
Filip Chytrý
Virus Analyst

mrmillersr

  • Guest
Can someone tell me when the next update is?  I want to access this website today.  Is there a way I can bypass the program being blocked?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
dont know when next VPS release is....or they may release it with next stream update..

you can try turn off web shield when entering that site....but if that works turn it on again before you go to any other site




mrmillersr

  • Guest
I turned off web shield and it still blocked me from entering the site.  I guess I will just delete the program and go with AVG instead.  This is too much aggravation to go through if someone needs to access a site that doesn't have any problems and software gives a false positive.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
and what do you do when AVG has a FP?.....use Norton....and when that have a FP?

all AV have FP....relax and wait untill fixed, its not end of the world if you cant access that site for a couple hours...is it?


Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
I completely agree with Pondus.

It doesn't seem realistic to switch AVs when you could either a: visit the site with avast! disabled or b: wait a few < 8 hours for the site to be unblocked.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Hi !Donovan,

Couldn't this be a valid IP block, re: http://forums.malwarebytes.org/index.php?showtopic=25012
216563 sites on that same IP and there are quite some baddies
Also see the IP from where the site mitigated: http://urlquery.net/report.php?id=1762131

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!