Author Topic: HTML: Iframe-inf  (Read 4583 times)

0 Members and 1 Guest are viewing this topic.

hennom

  • Guest
HTML: Iframe-inf
« on: August 06, 2009, 05:12:49 PM »
Some of our clients with Avast software have been complaining about this HTML: Iframe-inf malware.

They sent us screenshots so that we can see these errors for ourselves.

Is there anything to worry about on our site (www.sonicinformed.co.za)?

There is no client side javascript or Iframes on it?

Kind Regards
Henno

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: HTML: Iframe-inf
« Reply #1 on: August 06, 2009, 05:46:03 PM »
Please 'modify' your post change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites, thanks.

Well I have just visited the site using firefox and no alert (takes forever to load on dial-up very media heavy). Also just loaded it in Avant browser an IE clone and again no alert. So what is the specific page that is being alerted on (nothing on the home page and on dial-up I can't go rummaging) ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline scythe944

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2913
    • My Tech Blog
Re: HTML: Iframe-inf
« Reply #2 on: August 06, 2009, 05:49:00 PM »
I didn't see anything on the main page either.  Perhaps one of your sub-pages?

Uploading the screenshot from one of your customers might be beneficial as well.
For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum

hennom

  • Guest
Re: HTML: Iframe-inf
« Reply #3 on: August 06, 2009, 05:52:07 PM »
It was on the home page!

I have attached the Error screen from our clients!

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: HTML: Iframe-inf
« Reply #4 on: August 06, 2009, 05:56:00 PM »
This what google safe browsing has to say about sonicinformed.com


http://www.google.com/safebrowsing/diagnostic?site=sonicinformed.com

what say?

edit :
Quote
Malicious software includes 4 trojan(s).

Malicious software is hosted on 1 domain(s), including xg9.ru
« Last Edit: August 06, 2009, 06:11:26 PM by nmb »

Offline scythe944

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2913
    • My Tech Blog
Re: HTML: Iframe-inf
« Reply #5 on: August 06, 2009, 05:57:25 PM »
Hmm... My VPS version is: 090806-0

Maybe they have included it in the new VPS database.  Or, maybe you got rid of whatever Avast was complaining about.
For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum

spg SCOTT

  • Guest
Re: HTML: Iframe-inf
« Reply #6 on: August 06, 2009, 05:59:11 PM »
That is not the link you posted before

6  Iframes, linking to malicious domains. They are also redirecting to a non standard port 8080, possibly to avoid scanning...


Offline scythe944

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2913
    • My Tech Blog
Re: HTML: Iframe-inf
« Reply #7 on: August 06, 2009, 06:00:45 PM »
oh, sonicinformed.com....

Yeah, that's popping up warnings.
For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum

hennom

  • Guest
Re: HTML: Iframe-inf
« Reply #8 on: August 06, 2009, 07:04:33 PM »
Thank you everyone for helping with this problem.

We will sort out the .com server.

Both co.za and .com sites redirect to the co.za domain but some of the images are on the .com domain.

hennom

  • Guest
Re: HTML: Iframe-inf
« Reply #9 on: August 06, 2009, 07:06:25 PM »
One more thing.

Great job avast for picking this up. ;D

Black3agl3

  • Guest
Re: HTML: Iframe-inf
« Reply #10 on: August 06, 2009, 07:19:00 PM »
oh, sonicinformed.com....

Yeah, that's popping up warnings.
really? did not get any?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: HTML: Iframe-inf
« Reply #11 on: August 06, 2009, 09:21:19 PM »
You won't have as it wasn't the URL that was initially given that was infected, which is why we asked for a specific URL (that in the image) which has been hacked.

Personally I would suggest that you stay away from suspect sites, unless you are more experienced (than I believe you are) and are prepared to get infected and having been infected be able to put things back as they were before infection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Cr8Znbnny

  • Guest
Re: HTML: Iframe-inf
« Reply #12 on: August 11, 2009, 06:55:08 PM »
I went to F-Secure.com to scan my PC using IE8. While the files the scanner were downloading to the Local Settings\Temp folder were 93% complete...Avast! alerted me of a 61860 byte file. The file name was jpeg.xmd. Avast! flagged it as containing signs of an HTML:IFrame-inf.

Since I was not sure if it was a false positive or if  F-Secures servers were hacked to serve malware. I immediatly halted the downloading process at 93% confused if the actual files were actual malware signatures or that like Spybot S&D sometimes malware signatures turn up false positives.

Feeling as paranoid as I was, I promptly erased the subdirectories and files under the Local Settings\Temp folder.The name of the folders under Temp folder are Online Scanner\updates\0\infopack_fswserver.f-secure.com_80_377428708.


I erased the files by deleting them to the recycle bin and ran CCleaner with the 3passes algorithim
In this folder was were Avast! found the file "infopack_fswserver.f-secure.com_80_377428708".

Anyone know if this is a false positive or that the file is indeed malicious?

An issue I would like to report, (I  sincerly apoligize for including it in this topic since I am new to posting) is that Avast! hangs at a folder:

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95. This was since 2 Months ago or so. I think it only happens when performing a thorough scan.I perform the Thorough scan just incase there a packed and obfuscated viruses on disc.

Avast! is awesome! thanks everyone!