Author Topic: SZ0M.garo.gdn Detected-False Positive?  (Read 3698 times)

0 Members and 1 Guest are viewing this topic.

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
SZ0M.garo.gdn Detected-False Positive?
« on: September 04, 2017, 09:47:14 PM »
I am using Avast Free Version with the latest updates.

On Mon Sept 4 at Noon Pacific, I had my Opera browser open (with the latest updates) and a warning message stated 'We safely aborted connection on sz0m.garo.gdn because it was infected with URL:Mal.'

Threat: URL: Mal
URL: http://sz0m.garo.gdnl?Opera.exe
Detected by Web Shield
Status: Connection Aborted

I checked the Virus Vault but nothing was listed so a Smart Scan and a Full Virus Scan were run but nothing was detected during either scan.

An Anti-Malware scan was also run (with the latest updates) but nothing was detected either.

Was this a false positive since Avast detected an issue within Opera.exe specifically? If someone could look into it and advise, it would be appreciated.
« Last Edit: September 04, 2017, 10:00:07 PM by Spiritual2016 »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #1 on: September 04, 2017, 10:04:26 PM »
Ofcourse there is nothing in the chest as there is nothing to place there.
It was the webshield that blocked a blacklisted site.

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #2 on: September 04, 2017, 11:05:30 PM »
The only page that was open in my Opera browser was my Hotmail inbox-Why would that be blacklisted?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #3 on: September 04, 2017, 11:16:43 PM »
Read your first post.
It wasn't Hotmail that was blocked.

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #4 on: September 04, 2017, 11:37:02 PM »
You need to be clearer in what you are talking about.

I had two pages open in Firefox (Hotmail and Craigslist) and one page open in Opera (another Hotmail account).

What website was blocked?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48608
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #5 on: September 04, 2017, 11:38:36 PM »
You posted the site in your original post.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #6 on: September 04, 2017, 11:51:37 PM »
'What was the original website and what browser was it blocked on?'

I only visited Hotmail and Craigslist so how could a non-visited website be blocked?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #7 on: September 05, 2017, 12:03:28 AM »
'What was the original website and what browser was it blocked on?'

I only visited Hotmail and Craigslist so how could a non-visited website be blocked?

Either of those sites or individual page that you visit could have a 3rd party link to another site, one that is on list of sites considered to be malicious or infected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #8 on: September 05, 2017, 12:14:08 AM »
DavidR:

I visit Hotmail and Craigslist multiple times each day and never had an Avast warning that blocked it so why would Avast block it this one time?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48608
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #9 on: September 05, 2017, 12:39:37 AM »
Look at your first post:
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #10 on: September 05, 2017, 01:09:55 AM »
DavidR:

I visit Hotmail and Craigslist multiple times each day and never had an Avast warning that blocked it so why would Avast block it this one time?

It doesn't really matter how many times you have used the site, 'something' on it is trying to access what is considered a malicious site.  This could even be as common as an advert on that page being delivered by an ad source this is commonly called 'malvertising' it could be something else entirely. 

Something is trying to connect to sz0m.garo.gdn and that is subsequently trying to connect again to a site considered malicious.  What that might be I don't know, I didn't venture into the site to find any 3rd party links.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #11 on: September 05, 2017, 01:14:52 AM »
DavidR Only:

What 'is' sz0m.garo.gdn Opera.exe though?

Is it a website? If so, what type of website?
Was Firefox or Opera attemptuing to connect to it?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #12 on: September 05, 2017, 01:57:37 AM »
It is in two parts 1. the site/url that is at issue and 2. the process trying to access it, in this case your browser Opera.

As you can see from my images I used firefox to access sz0m.garo.gdn to trigger the alert to be able to show the images.

Yes it is a website/url - I have no idea what type of website it is.  The process/browser used is immaterial, you happened to be using your browser and a site that you connected to (Hotmail and Craigslist) could have an external (3rd party) link to the sz0m.garo.gdn site and that inadvertently triggered the alert.

If using Hotmail to browse your email, there is also a possibility one of your emails had an external link.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #13 on: September 05, 2017, 02:04:31 AM »
DavidR Only:

Thanks for the information-Obviously, Web Shield did its job by blocking this malicious activity from entering my computer, correct?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: SZ0M.garo.gdn Detected-False Positive?
« Reply #14 on: September 05, 2017, 04:54:48 AM »
Read your first post !