![]() |
|
#1
|
|||
|
|||
|
Hi,
I am a user of animecrazy.net, and dramacrazy.net, and since the last signature update I've noticed that any video iframes show up as a false positive, JS/TrojanDownloader.Iframe.NKE trojan. Like for instance: -dramacrazy.net/korean-drama/city-hunter-episode-2/ speedy joe(satsukai.com) mirrors use iframes to show, and I've tried to identify with multiple virus scanners, and only yours shows this false positive. If you watch the same video on the actual satsukai.com site -satsukai.com/get_video.php?video=17762 Nothing shows up, meaning it's not the actual page. Another non iframe mirror: -dramacrazy.net/korean-drama/city-hunter-episode-2/146491 see no virus Or for instance try this: -dramacrazy.net/korean-drama/city-hunter-episode-19/163500 same issue using another iframe site. If you check the actual Iframe page in a new tab, no virus. If you try the actual site with a non iframe mirror, it shows no virus so I'm ruling out ads, comprimised pages, etc. But when you try a page with an video that comes through an iframe it calls it a virus. No files are downloaded from that site. No viruses come from it. It's just a video player in an iframe. Here's an image of the eset popup i get. http://img69.imageshack.us/img69/5350/unled1iy.png I need this to be fixed as it's not a virus and is on every page i view except the other mirrors, and getting quite annoying fast. Thanks! |
|
#2
|
|||
|
|||
|
Hello mavi
If you think there is a " False Positive Website" you can always report it to Eset using the guide in this link : http://kb.eset.com/esetkb/index?page...=1312054995198 Best Regards NoobStick |
|
#3
|
||||
|
||||
|
I saw similar detections in the ScrInject signature
anyway a frame with a minimal size is always suspicious
__________________
Pentium M| 512 RAM ESET NOD32 Antivirus 5 ESET Smart Security 6 RC |
|
#4
|
|||
|
|||
|
Quote:
|
|
#5
|
||||
|
||||
|
An apparent iframe exploit, as NoobStick noted, submit the false postive to ESET for analysis.
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#6
|
|||
|
|||
|
Please keep in mind, that a massive iFrame Injection is going on right now and that nod32 just might have saved your a**
http://blog.armorize.com/2011/07/wil...n-ongoing.html |
|
#7
|
||||
|
||||
|
do you understand what is a false positive ?
a same file could be ok in another website or mirror but it dont means it is a false positive. Can just means that the another website or mirror is NOT infected !!! submit website and/or file to Eset, if it is a false alert and the video or file is really ok, they will correct this in a next virus db update |
|
#8
|
|||
|
|||
|
FYI. mavi is talking about the same site at Malwarebytes Forum as well, see what they answered here:
http://forums.malwarebytes.org/index...howtopic=87729
__________________
OpenDNS ESET Smart Security -A Heavy product is not the same as a Bloated product and vice versa- Last edited by SweX : July 31st, 2011 at 03:16 PM. |
|
#9
|
||||
|
||||
|
Thank you for this, Swex
Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#10
|
|||
|
|||
|
This is the very reason why I don't use malware bytes, they veer too far on the edge of false positives. I know plenty of good sites that are on ecatel, that are anime sites.
With that said, this iframe issue affects pretty much any site that serves media through an iframe. It's too major of an issue to continue as is. Peace out, hope it gets resolved soon. |
|
#11
|
||||
|
||||
|
In order to fix the problem cease usage of the obfuscation. You can find detail explanation here:
http://blog.eset.com/2011/05/17/obfu...-a-tangled-web |
|
#12
|
|||
|
|||
|
Quote:
__________________
OpenDNS ESET Smart Security -A Heavy product is not the same as a Bloated product and vice versa- |
|
#13
|
||||
|
||||
|
Thank you for this, danieln
Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#14
|
|||
|
|||
|
Quote:
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|