Author Topic: Hilarious Web Shield false positive  (Read 1638 times)

0 Members and 1 Guest are viewing this topic.

Offline Jack Crawford

  • Newbie
  • *
  • Posts: 1
Hilarious Web Shield false positive
« on: April 24, 2019, 06:40:18 AM »
Avast Web Shield just aborted my connection to YouTube because it was allegedly infected with a trojan JS:ScriptPE-inf

(fwiw, the video was https://www.youtube.com/watch?v=wh_WGWii7UE)

...I'm pretty sure YouTube's safe. (I hope that I'm not actually the fool in this case and that this isn't a symptom of some larger underlying problem with my browser being infected or something, but I'm fairly certain I'm clean.)



Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Hilarious Web Shield false positive
« Reply #1 on: April 24, 2019, 06:51:16 AM »
Hi, just tested your YT link, but didn't get any Avast warning.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Hilarious Web Shield false positive
« Reply #2 on: April 24, 2019, 09:41:44 AM »
Hi,
I also cannot reproduce.
How this can happen:
1. a link in youtube comments pointing to a blocked URL;
2. infected browser (for example extension that we block);
3. MitM attack (router or ISP) injecting blocked URLs to your content.

Does it still happen? Does it happen in a different browser? On a different device in the same network? Does it happen on the same device in a different network?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5599
  • Spartan Warrior
Re: Hilarious Web Shield false positive
« Reply #3 on: April 24, 2019, 05:21:46 PM »
Hi HonzaZ,

Also cannot reproduce if using FF 66.0.3 but alert if using Avast Secure Browser, active block.  See below:

Only difference in extensions is Windows Defender Browser Protection is in use in ASB.
« Last Edit: April 24, 2019, 08:49:42 PM by mchain »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Hilarious Web Shield false positive
« Reply #4 on: April 25, 2019, 09:40:30 AM »
I have been able to find it in stats database. It is caused by this blocked URL: connermcd[.]com (the website of the author of the video). I am unblocking it now!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5599
  • Spartan Warrior
Re: Hilarious Web Shield false positive
« Reply #5 on: April 26, 2019, 03:31:16 AM »
Thanks HonzaZ.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801