Author Topic: False positives ?  (Read 2057 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
False positives ?
« on: March 05, 2016, 06:41:21 PM »
A couple of the websites that I regularly visit have started triggering my Avast Free.

I've messaged the admins of both who seem to think there's nothing wrong on their sites but I can't access them with Avast active (and am reluctant to turn it off just in case they are wrong)

the message Avast gives me for each site is shown below

Website:http://sendtheeighth.blogspot.co.uk/

Infection
URL: http://sendtheeighth.blogspot.co.uk/|{gzip}
Infection: HTML:Script-inf
Process: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Website

Infection
URL: http://www.worldsendradio.com/
Infection: URL:Mal
Process: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: False positives ?
« Reply #1 on: March 05, 2016, 07:07:56 PM »
One detection is for iFrame malcode: http://www.isithacked.com/check/http%3A%2F%2Fsendtheeighth.blogspot.co.uk
The other one might be probably harmless.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: False positives ?
« Reply #2 on: March 05, 2016, 07:08:51 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: False positives ?
« Reply #3 on: March 05, 2016, 07:54:16 PM »
Quote
Infection
URL: hxxp://sendtheeighth.blogspot.co.uk/|{gzip}
Infection: HTML:Script-inf
Process: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Two detections
https://www.virustotal.com/nb/file/065bd1beaaa8fff28248ec3ecd65d9ad1333aa9bc434bcd2647138fd0481f6c6/analysis/1457203958/


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: False positives ?
« Reply #4 on: March 05, 2016, 10:30:59 PM »
The iFrame links: <iframe allowtransparency="true" class="reactions-iframe" frameborder="0" name="reactions" scrolling="no" src="-https://www.blogger.com/blog-post-reactions.g?options=%5Bfunny,+interesting,+cool%5D&amp;textColor=%23999999#-http://sendtheeighth.blogspot.com/2016/03/site-news-releases-cool-stuff.html"></iframe>
<iframe allowtransparency="true" class="reactions-iframe" frameborder="0" name="reactions" scrolling="no" src="-https://www.blogger.com/blog-post-reactions.g?options=%5Bfunny,+interesting,+cool%5D&amp;textColor=%23999999#-http://sendtheeighth.blogspot.com/2016/02/gallery-darklands-formoraic-idruaada-by.html"></iframe>
<iframe allowtransparency="true" class="reactions-iframe" frameborder="0" name="reactions" scrolling="no" src="-https://www.blogger.com/blog-post-reactions.g?options=%5Bfunny,+interesting,+cool%5D&amp;textColor=%23999999#-http://sendtheeighth.blogspot.com/2016/02/gallery-darklands-infernii-krull-by-sven.html"></iframe>
<iframe allowtransparency="true" class="reactions-iframe" frameborder="0" name="reactions" scrolling="no" src="-https://www.blogger.com/blog-post-reactions.g?options=%5Bfunny,+interesting,+cool%5D&amp;textColor=%23999999#-http://sendtheeighth.blogspot.com/2016/02/gallery-kingdom-death-lion-knight-2nd.html"></iframe>
<iframe allowtransparency="true" class="reactions-iframe" frameborder="0" name="reactions" scrolling="no" src="-https://www.blogger.com/blog-post-reactions.g?options=%5Bfunny,+interesting,+cool%5D&amp;textColor=%23999999#---http://sendtheeighth.blogspot.com/2016/01/galllery-kingdom-death-white-knight.html"></iframe>
<iframe src="-http://www.gamewire.belloflostsouls.net/widget/widget-iframe.html" width="300px" height="650px" scrolling="no"></iframe>

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: False positives ?
« Reply #5 on: March 06, 2016, 11:53:41 PM »
Thanks for the information folks

I've pointed the admins here so they can see for themselves

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: False positives ?
« Reply #6 on: March 07, 2016, 12:28:49 AM »
You're welcome.