Author Topic: NOT an FP!! (false positive)  (Read 6491 times)

0 Members and 1 Guest are viewing this topic.

Rick F

  • Guest
NOT an FP!! (false positive)
« on: June 21, 2009, 05:20:15 AM »
I'm a moderator of a forum for musicians (tuba and euphonium) and frequent this forum several times throughout the day.  This morning I had no trouble (no warnings from avast), but after an avast update sometime today, I now get avast popping up warning me of a virus.

It says "Sign of HTML: "Iframe-inf" has been found in "HTTP:/222.231.60.19/seraph/door/iisHelp/help.js" file

I clicked 'terminate connection' but my browser stayed open (IE-6).  Ran a full scan of my HDD with avast and nothing was found.  Went back to the site and after I clicked on the 3rd folder I get the warning again.  I tried this about 5 times with same result.  Then running a full avast scan again with nothing found.  The last time I clicked 'report as FP'... but it hasn't been submitted yet because there hasn't been an vps update since then.

See attached text file my warning log.

<<< edit >>>

Found out this is NOT a false positive. Got a notice a little while ago from the forum admn that all sites on this particular server were hit with this malware (more than 100 sites affected). This site was taken down until it is completely clean.

Thanks.
« Last Edit: June 22, 2009, 04:41:25 AM by Rick F »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11856
    • AVAST Software
Re: Possible FP (false positive)?
« Reply #1 on: June 21, 2009, 11:42:43 AM »
Those iframes at the bottom, pointing to Chinese sites, look a bit suspicious to me...

Rick F

  • Guest
Re: Possible FP (false positive)?
« Reply #2 on: June 21, 2009, 06:16:38 PM »
Thanks for replying Igor.

Maybe it's not a FP as it seems to have gotten worse today. Now when I try going to the main site of "dwerden(dot)com", I get the alarm.  I didn't notice any frames at the bottom of the page.  But when I enter the URL listed in the warning file I attached, avast sounds the alarm. 

I've contacted the site administrator and he's looking into it.

Thanks.


Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89211
  • No support PMs thanks
Re: Possible FP (false positive)?
« Reply #3 on: June 21, 2009, 07:57:13 PM »
The Terminate Connection only terminates the suspect element which has been detected and not the complete connection and it doesn't close your browser either.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Possible FP (false positive)?
« Reply #4 on: June 21, 2009, 08:35:54 PM »
The Terminate Connection only terminates the suspect element which has been detected and not the complete connection and it doesn't close your browser either.
Thanks for making that clear... I've aborted the connection of one site yesterday and then, suddenly, the site appears (rendered) in the browser... I was thinking that WebShield was not working...
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Possible FP (false positive)?
« Reply #5 on: June 21, 2009, 09:01:39 PM »
Hi Rick F.,

Last time that suspicious content was found on this site was 2009-06-21.
Malicious software includes 4 trojan(s), 4 exploit(s). Successful infection resulted in an average of 1 new process(es) on the target machine.

Malware is being hosted on 4 domains, e.g.: elfah.net/, cc9n.cn/, qiqijs.com/.

Two domains seem to fuction as intermediaries for spreading malware to visitors of this site, e.g.: 222.231.60.0/, elfah.net/.

This site was hosted on 1 network(s) including AS20021 (LNH),

(Level: 1) Url checked: (script source)
htxp://count25.51yes.com/click.aspx?id=251472952&logo=1
Zeroiframes detected on this site: 1


polonus
« Last Edit: June 21, 2009, 10:28:36 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89211
  • No support PMs thanks
Re: Possible FP (false positive)?
« Reply #6 on: June 21, 2009, 09:22:08 PM »
The Terminate Connection only terminates the suspect element which has been detected and not the complete connection and it doesn't close your browser either.
Thanks for making that clear... I've aborted the connection of one site yesterday and then, suddenly, the site appears (rendered) in the browser... I was thinking that WebShield was not working...

Yes, that happens on occasion, usually where the infected/suspect element isn't actually the html page you are browsing. Though some browsers may try to complete the download.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Rick F

  • Guest
Re: Possible FP (false positive)?
« Reply #7 on: June 21, 2009, 10:26:39 PM »
Thanks for that explanation David.

polonus,

Not sure what you're saying.  Are you saying for a fact that the site is hosting a nasty?

I noticed that site is down right now as I get a debug screen.

Thanks.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Possible FP (false positive)?
« Reply #8 on: June 21, 2009, 10:36:48 PM »
Hi RickF,

The iframe virus are redirecting to chinese domain which was severely affected by malwares which will lead to theft of secured data from your system. If you didn't care for these virus then the virus will eat your whole site.

How to Remove Iframe virus?
Iframe tags will be written just below the body tag. Follow the steps to remove virus.
1. Login to your FTP & edit the file which you've got iframe tag.

2. Look for the iframe tag just below the Body or Head tag.

3. Remove the coding & overwrite the file.

4. Now right click the file and click properties/File attributes and make it to "444". So that no hackers have privilege to write the file with iframe code.

5. Once you've cleaned this, the other type of virus will slowly raise, that is it will search the files that are included on the index.php file (ie dbconnect.php, general.php, configure.php, common.php, functions.php, classes.php etc) and it will write a php coding at the top of the page where it will dynamically write the javascript code at the time of execution of the file in the web - browser. The script will redirect the page to the sites mentioned in my above posting - these schemes fall in the realm of the gumblar/beladen/etc. massive website hacks.

6. To remove these type of error carefully look into the above mentioned filename, you can easily find out the php coding at the top of the page. Just remove the coding and make sure it is write protected, so that the php coding wont be written.

7. Still you cant find the solution, just comment, also change your log-in passwords and harden them,

polonus
« Last Edit: June 21, 2009, 10:41:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Rick F

  • Guest
Re: Possible FP (false positive)?
« Reply #9 on: June 21, 2009, 11:34:51 PM »
Thanks,

I don't have the authority myself to do this, but I've shared the link to this discussion with the forum admn. Hopefully this information you've provided will help.

I've run avast, Malwarebytes, SAS, Spy Bot S+D on my computer, and nothing is found so I think avast Webshield has protected my PC.

Thanks again.

Rick F

  • Guest
Re: NOT an FP!! (false positive)?
« Reply #10 on: June 22, 2009, 04:40:52 AM »
I edited my original post to say, this is NOT a false positive. Got notice a little while ago from the forum admin that all sites on a particular server were hit with this malware (more than 100 sites affected). This site was taken down until it is completely clean.

I noticed that Google is now warning PC users of any links that might be offered by a Google search to that site with the following message: "Warning - visiting this web site may harm your computer!"

Thanks guys. I appreciate the help.  I'm glad avast has a WebShield. I consider the "WebShield" an 'early' defense mechanism.
« Last Edit: June 22, 2009, 04:43:33 AM by Rick F »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89211
  • No support PMs thanks
Re: NOT an FP!! (false positive)
« Reply #11 on: June 22, 2009, 03:42:56 PM »
You might want to look at this latest avast blog on google's search database being used by malware creators.

http://blog.avast.com/2009/06/18/google-new-malware-hosting/#more-214
Quote
A new type of malware has been found today which uses the Google search engine database for hosting.  Werner Klier (virus researcher from GData) pointed us to one very puzzling result of Google search. This result was detected as malware with avast! from the beginning. It is however a very interesting approach from malware creators – using Google to host their malware.

Mainly a heads up not to take all that appears in google searches as safe.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Rick F

  • Guest
Re: NOT an FP!! (false positive)
« Reply #12 on: June 23, 2009, 04:43:00 AM »
Thanks for the additional info David.  This forum that was infected doesn't use php software.  I forget what mfg it is. That's scary though!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89211
  • No support PMs thanks
Re: NOT an FP!! (false positive)
« Reply #13 on: June 23, 2009, 05:32:24 PM »
You're welcome, you really have to keep on your toes now as there are many malicious creative people looking to exploit vulnerabilities. So it is important to keep and content management software up to date.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security