Author Topic: Another case of JS:ScriptIP-inf [TrJ], most likely false positive, need help  (Read 8656 times)

0 Members and 3 Guests are viewing this topic.

REDACTED

  • Guest
Hello, I came here in order to try to figure out why Avast reports my site as having the above mentioned virus.

I have a forum and one member who obviously uses Avast reported to me that the site is being blocked (please see attachment).

However, Sucury doesn't complain - https://sitecheck.sucuri.net/results/forum.italkmoney.com - and if you click on "Blacklist STatus" tab you'll see all clear marks.

So, could some of you who use Avast doublecheck the result, and if it is indeed positive, could someone from Avast look into this?

Best regards!

Ah yes, the site in question is http://forum.italkmoney.com

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Quote
Hello, I came here in order to try to figure out why Avast reports my site as having the above mentioned virus.
avast say trojan, not virus > JS:ScriptIP-inf [TrJ] = Trojan

It means there is a java script containing a blacklisted URL or loading something from a blacklisted URL



REDACTED

  • Guest
Well, thanks for correction, but I still need clarification of the report...

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
If you think it is wrong, you may report / contact avast lab > https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
« Last Edit: December 20, 2016, 06:51:41 PM by Eddy »

REDACTED

  • Guest
There's nothing to complaint about Sucuri report, so I'll contact Avast on the above mentioned link.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Avast is blocking the connection because it tries to execute JS code which contains a blocked URL (mycashbot[.]com).

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
« Last Edit: December 22, 2016, 05:52:29 PM by Pondus »

REDACTED

  • Guest
First of all thanks for all the information provided.

So, if I understood everything correctly, the reason for Avast to react was Tynt script?

If so, I've removed it, and looks like the whole Tynt site was moved to 33Across, with new script for the same purpose and a lot of other things. Anyway, at the moment the script is gone, and it should not alert Avast any longer.

Could someone confirm it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
« Last Edit: December 22, 2016, 06:37:01 PM by Pondus »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
It for sure is still there.
On the main page already two links to mycashbot

REDACTED

  • Guest
What do you mean exactly by "On the main page already two links to mycashbot"?

OK, disregard, I got it.
« Last Edit: December 22, 2016, 06:50:02 PM by sinip »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
see screenshot


REDACTED

  • Guest
Yep, I've got it in the meantime. :) And amended myself.

The "funny" part is that Mycashbot is not blocked by either Eset, Firefox phishing protection or Sucuri, it is clean and indexed by Google and yet it "raises flag" on Avast. Better yet, there is NO online scanner available at Avast (that I know of) where one like me could check if a site is flagged for one reason or another by Avast, before including link to it (or more precisely to a banner on its site) into your site. So it pretty much sucks, IMHO.

Anyway, all the links to Mycashbot are now gone. What's the verdict this time?
« Last Edit: December 22, 2016, 07:06:35 PM by sinip »