Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 30th, 2011, 02:41 PM
mavi mavi is offline
Infrequent Poster
 
Join Date: Jul 2011
Posts: 4
Default False Positive Website

Hi,

I am a user of animecrazy.net, and dramacrazy.net, and since the last
signature update I've noticed that any video iframes show up as a
false positive, JS/TrojanDownloader.Iframe.NKE trojan.

Like for instance:
-dramacrazy.net/korean-drama/city-hunter-episode-2/ speedy
joe(satsukai.com) mirrors use iframes to show, and I've tried to identify with
multiple virus scanners, and only yours shows this false positive.

If you watch the same video on the actual satsukai.com site
-satsukai.com/get_video.php?video=17762

Nothing shows up, meaning it's not the actual page.

Another non iframe mirror:
-dramacrazy.net/korean-drama/city-hunter-episode-2/146491
see no virus

Or for instance try this:
-dramacrazy.net/korean-drama/city-hunter-episode-19/163500
same issue using another iframe site.

If you check the actual Iframe
page in a new tab, no virus.

If you try the actual site with a non iframe mirror, it shows no virus so I'm ruling out ads, comprimised pages, etc. But
when you try a page with an video that comes through an iframe it
calls it a virus.

No files are downloaded from that site. No viruses come from it. It's
just a video player in an iframe.

Here's an image of the eset popup i get.

Name:  Clipboard02.jpg
Views: 1043
Size:  14.2 KB
http://img69.imageshack.us/img69/5350/unled1iy.png

I need this to be fixed as it's not a virus and is on every page i
view except the other mirrors, and getting quite annoying fast.

Thanks!
  #2  
Old July 30th, 2011, 03:48 PM
NoobStick NoobStick is offline
Guest
 
Join Date: Jun 2011
Posts: 0
Default Re: False Positive Website

Hello mavi
If you think there is a " False Positive Website" you can always report it to Eset using the guide in this link : http://kb.eset.com/esetkb/index?page...=1312054995198

Best Regards

NoobStick
  #3  
Old July 30th, 2011, 04:20 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: False Positive Website

I saw similar detections in the ScrInject signature

anyway a frame with a minimal size is always suspicious
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #4  
Old July 30th, 2011, 09:19 PM
mavi mavi is offline
Infrequent Poster
 
Join Date: Jul 2011
Posts: 4
Default Re: False Positive Website

Quote:
Originally Posted by toxinon12345
I saw similar detections in the ScrInject signature

anyway a frame with a minimal size is always suspicious
But the frame size is 700x400.
  #5  
Old July 31st, 2011, 03:01 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,141
Post Re: False Positive Website

An apparent iframe exploit, as NoobStick noted, submit the false postive to ESET for analysis.
  #6  
Old July 31st, 2011, 06:30 AM
no_idea no_idea is offline
Regular Poster
 
Join Date: Apr 2009
Posts: 82
Default Re: False Positive Website

Please keep in mind, that a massive iFrame Injection is going on right now and that nod32 just might have saved your a**

http://blog.armorize.com/2011/07/wil...n-ongoing.html
  #7  
Old July 31st, 2011, 10:10 AM
piranha's Avatar
piranha piranha is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Laval, Québec, Canada
Posts: 623
Default Re: False Positive Website

do you understand what is a false positive ?

a same file could be ok in another website or mirror but it dont means it is a false positive. Can just means that the another website or mirror is NOT infected !!!

submit website and/or file to Eset, if it is a false alert and the video or file is really ok, they will correct this in a next virus db update
  #8  
Old July 31st, 2011, 03:08 PM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,653
Default Re: False Positive Website

FYI. mavi is talking about the same site at Malwarebytes Forum as well, see what they answered here:
http://forums.malwarebytes.org/index...howtopic=87729
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-

Last edited by SweX : July 31st, 2011 at 03:16 PM.
  #9  
Old July 31st, 2011, 05:39 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,141
Post Re: False Positive Website

Thank you for this, Swex

Quote:
Originally Posted by SweX
FYI. mavi is talking about the same site at Malwarebytes Forum as well, see what they answered here:
http://forums.malwarebytes.org/index...howtopic=87729
  #10  
Old July 31st, 2011, 06:16 PM
mavi mavi is offline
Infrequent Poster
 
Join Date: Jul 2011
Posts: 4
Default Re: False Positive Website

This is the very reason why I don't use malware bytes, they veer too far on the edge of false positives. I know plenty of good sites that are on ecatel, that are anime sites.

With that said, this iframe issue affects pretty much any site that serves media through an iframe. It's too major of an issue to continue as is.

Peace out, hope it gets resolved soon.
  #11  
Old August 1st, 2011, 06:39 AM
danieln's Avatar
danieln danieln is offline
Eset Staff
 
Join Date: Jan 2009
Posts: 112
Default Re: False Positive Website

In order to fix the problem cease usage of the obfuscation. You can find detail explanation here:
http://blog.eset.com/2011/05/17/obfu...-a-tangled-web
  #12  
Old August 1st, 2011, 07:15 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,653
Default Re: False Positive Website

Quote:
Originally Posted by siljaline
Thank you for this, Swex
You're welcome mate
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #13  
Old August 1st, 2011, 08:11 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,141
Post Re: False Positive Website

Thank you for this, danieln

Quote:
Originally Posted by danieln
In order to fix the problem cease usage of the obfuscation. You can find detail explanation here:
http://blog.eset.com/2011/05/17/obfu...-a-tangled-web
  #14  
Old August 3rd, 2011, 03:11 AM
mavi mavi is offline
Infrequent Poster
 
Join Date: Jul 2011
Posts: 4
Default Re: False Positive Website

Quote:
Originally Posted by danieln
In order to fix the problem cease usage of the obfuscation. You can find detail explanation here:
http://blog.eset.com/2011/05/17/obfu...-a-tangled-web
Is that the problem? Can't you guys just whitelist the three sites (AnimeCrazy.Net/DramaCrazy.Net) as they are virus free but are just running into the obfuscated issue?
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:06 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums