Author Topic: Probably false positive on "Tim & Eric" message board  (Read 8017 times)

0 Members and 1 Guest are viewing this topic.

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Probably false positive on "Tim & Eric" message board
« on: September 30, 2011, 08:19:48 PM »
Clicking on the different pages in this thread is triggering the network shield in Avast. This is a legit message board for a TV show not some shady porn site. Try clicking on page 4 or page 3 and see if Avast blocks something. Try again if it doesn't block the first time. http://www.tgttm.com/jefferton/viewtopic.php?f=24&t=5486&start=25

And the supposedly malicious blocked urls involve image files. The last blocked connection was to http://www.tgttm.com/jefferson/images/smilies/sad.gif. But it seems to block something different each time.

I use Firefox 7 and the free version of Avast if that makes any difference.


« Last Edit: September 30, 2011, 08:21:48 PM by mbd35 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Probably false positive on "Tim & Eric" message board
« Reply #1 on: September 30, 2011, 08:32:22 PM »
The fact that it is a legitimate board doesn't stop it becoming hacked/infected, possibly more so if it is a popular site.

If the site has been infected it wouldn't take long before the reported detections by the web shield triggered the site being added to the malicious sites list and blocked by the Network Shield.

No problem accessing the first link, without avast alerting and no block by the network shield. I was also able to access the second link without avast alerting and no block by the network shield.

So I don't know what is wrong, ensure that you have the latest virus definitions update.

Nothing found on http://www.urlvoid.com/scan/tgttm.com or http://sitecheck.sucuri.net/scanner/ for the site.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #2 on: September 30, 2011, 08:38:27 PM »
I have the latest virus definitions.

The annoying thing is that you may have to click around the different thread pages for awhile before the network shield blocks anything. Sometimes it does it right away and sometimes it doesn't.

I wonder if anyone else can reproduce this.

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Re: Probably false positive on "Tim & Eric" message board
« Reply #3 on: September 30, 2011, 08:39:34 PM »
I got an alert the first time I clicked the 2nd link, but not when I went back to the site again. Very odd.
It alerted in hxxp://www.tgttm.com/favicon.ico
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Probably false positive on "Tim & Eric" message board
« Reply #4 on: September 30, 2011, 08:50:59 PM »
The favicon.ico is one of the favourite (excuse the pun) targets as that is loaded when the page loads, so if hacked it can trigger an exploit possibly taking you to a site that is blocked by avast.

So what is needed really is an screenshot of the alert window as that would show the target.

I have tried to capture the tgttm.com/favicon.ico, but I just get a server error  and if I just visit the hXXp://wXw.tgttm.com page it loads fine and no fabicon.ico file is loaded into the firefox address bar.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #5 on: September 30, 2011, 09:13:34 PM »
Whatever this was, it may have been resolved. It doesn't seem to be happening now. But we'll see.



Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #6 on: October 01, 2011, 10:19:21 PM »
Okay, it's doing it again. Here's a screen capture.

http://oi55.tinypic.com/2461ez6.jpg
« Last Edit: October 01, 2011, 10:27:58 PM by mbd35 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Probably false positive on "Tim & Eric" message board
« Reply #7 on: October 01, 2011, 10:57:52 PM »
Unfortunately this only makes it more strange the avast network shield alerting on that URL would normally be an indication that the 'domain' was in its malicious sites list. So I would expect the site to be blocked without actually alerting on a specific file. More so when that file is a .gif file, although just because the file type is .gif doesn't mean it is actually a .gif file. Though this time I have been able to download a copy of the file and find no malware 0/43, VirusTotal scan results. I have even viewed it as an image and it displays correctly, image1.

So I honestly don't understand what is going on with this intermittent detection.

There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Press (Media), issues.

- If you are reporting an FP, then you get another input field open, enter the web URL for the site you wish to submit for review, etc.


http://www.tgttm.com/jefferton/images/ranks/0.gif
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #8 on: October 02, 2011, 12:21:56 AM »
Another screen grab. Different file blocked this time. http://oi55.tinypic.com/f4c3k.jpg

I wonder what about this site is sporadically triggering the Avast alerts.

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #9 on: October 02, 2011, 06:19:17 PM »
There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Press (Media), issues.

- If you are reporting an FP, then you get another input field open, enter the web URL for the site you wish to submit for review, etc.

I reported the url and they were very prompt and helpful. It's being fixed in next update.

"Hello,
thanks a lot. It will be fixed in next VPS. Problem was that we blocked
IP used for tgttm.com and parallel used for other site with malicious
content"

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Probably false positive on "Tim & Eric" message board
« Reply #10 on: October 02, 2011, 07:27:15 PM »
Yes they are usually quite prompt to correct when it is confirmed.

There has just been a virus update, so you could check it out again and see if it is that one or the next which resolves it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mbd35

  • Jr. Member
  • **
  • Posts: 62
Re: Probably false positive on "Tim & Eric" message board
« Reply #11 on: October 02, 2011, 07:34:38 PM »
Yes they are usually quite prompt to correct when it is confirmed.

There has just been a virus update, so you could check it out again and see if it is that one or the next which resolves it.

I can see why Avast releases definition updates so often. They must have to correct little things like this all the time, in addition to keeping up with all the malware, infected sites, etc.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Probably false positive on "Tim & Eric" message board
« Reply #12 on: October 02, 2011, 07:38:33 PM »
There are many that say they don't release enough, on average it is two VPS updates per day and for the most part they aren't for corrections.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security