Author Topic: false positive ?  (Read 5704 times)

0 Members and 1 Guest are viewing this topic.

newkid215

  • Guest
false positive ?
« on: December 02, 2010, 05:34:23 PM »
Hello,
Would someone help to identify whether these two sites are actually virus or malware infected or it was false positive?

hxxp://www.preceptgroup.net/     (reported infected by JS:Illredir-CI [Trj])

hxxp://www.premierfitness.ca/overview   (reported infected with HTML:iframe-inf)

I remember that seeing around ten detections of iframe.inf from known business sites.  Is iframe.inf generates many false positive detections?

Some advice please,
Many thanks.  :)
« Last Edit: December 03, 2010, 02:11:14 PM by igor »

swarnava

  • Guest
Re: false positive ?
« Reply #1 on: December 02, 2010, 05:52:52 PM »
working fine here..

spg SCOTT

  • Guest
Re: false positive ?
« Reply #2 on: December 02, 2010, 06:08:42 PM »
Hi newkid215,

Please can you deactivate the links in your post(change http to hXXp) to prevent others potentially becoming infected.
EDIT: Thanks igor for doing this :)

1
Code: [Select]
hXXp://www.preceptgroup.net/menumachine/precept_drop_downs/menuspecs.js
This javascript file has been hacked, and a malicious site added at the end. It also tries to avoid detection by using port 8080, which obviously doesn't work. (capture.gif)

2
Code: [Select]
hXXp://www.premierfitness.ca/overview
avast! is alerting on a set of iframes that all have zero size (basically hidden). (capture2.gif)

I would say that both sites are infected.

Scott

@Swarnava/Heaven GOD

Based on what?
Why link the siteadvisor green tick?
« Last Edit: December 03, 2010, 07:14:54 PM by spg SCOTT »


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89025
  • No support PMs thanks
Re: false positive ?
« Reply #4 on: December 02, 2010, 06:49:47 PM »
Hello,
Would someone help to identify whether these two sites are actually virus or malware infected or it was false positive?
hXXp://www.preceptgroup.net/     (reported infected by JS:Illredir-CI [Trj])
hXXp://www.premierfitness.ca/overview   (reported infected with HTML:iframe-inf)

I remember that seeing around ten detections of iframe.inf from known business sites.  Is iframe.inf generates many false positive detections?

On the contrary the avast web shield has been extremely accurate in its detections in regard to hacked sites it is IMHO the best, when you consider the slew of hidden iframes to dubious looking domain names, I would say this is a good detection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: false positive ?
« Reply #5 on: December 03, 2010, 01:28:16 PM »
@Tenko,

You have also posted live links to the sites in question, could you please deactivate them, like in DavidR's post.


Please can you deactivate the links in your post(change http to hXXp) to prevent others potentially becomin infected.

Scott

Tenko

  • Guest
Re: false positive ?
« Reply #6 on: December 03, 2010, 01:33:42 PM »
I will change it now SCOTT

newkid215

  • Guest
Re: false positive ?
« Reply #7 on: December 03, 2010, 04:03:33 PM »
Thank you guys for all the good advices.
Next time will only post hxxp link.

Thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89025
  • No support PMs thanks
Re: false positive ?
« Reply #8 on: December 03, 2010, 05:23:18 PM »
You're welcome, I trust that you have now found and dealt with the offending scripts and iframe tags.

Then you only have to deal with the exploit that allowed the site to be hacked.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

swarnava

  • Guest
Re: false positive ?
« Reply #9 on: December 03, 2010, 06:00:43 PM »
Hi newkid215,

Please can you deactivate the links in your post(change http to hXXp) to prevent others potentially becomin infected.

1
Code: [Select]
hXXp://www.preceptgroup.net/menumachine/precept_drop_downs/menuspecs.js
This javascript file has been hacked, and a malicious site added at the end. It also tries to avoid detection by using port 8080, which obviously doesn't work. (capture.gif)

2
Code: [Select]
hXXp://www.premierfitness.ca/overview
avast! is alerting on a set of iframes that all have zero size (basically hidden). (capture2.gif)

I would say that both sites are infected.

Scott

@Swarnava/Heaven GOD

Based on what?
Why link the siteadvisor green tick?

i scan it specially with macafee & kaspersky..both are working fine :)