Tons of IFrame.B.Gen hits today

Discussion in 'ESET NOD32 Antivirus' started by bradtech, Aug 10, 2009.

Thread Status:
Not open for further replies.
  1. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    We haven't received such a file yet at samples[at]eset.com. The only link we've got wasn't detected by our v4, only access to the site was blocked.
     
  2. bradtech

    bradtech Guest

    I will try to get some of these files harvested..
     
  3. fcastro

    fcastro Registered Member

    Joined:
    Jul 6, 2007
    Posts:
    13
    Getting bp.specificclick.net hits from bing.com non stop.

    bp.specificclick.net at one point was responsible for malaware from the research I did.
     
  4. bradtech

    bradtech Guest

    afe.specificclick.html

    different [1][2] on each one.. Trying to \\computername\c$ into some boxes to harvest, but getting access denied any time I try to copy/paste.. Think NOD32 has it locked down.. I can copy others fine..
     
  5. bradtech

    bradtech Guest

    We are getting nothing but unable to clean.. Most of our users are non-local administrators..
     
  6. ittech

    ittech Registered Member

    Joined:
    Dec 5, 2007
    Posts:
    30

    try this link:

    [noparse]hxxp://afe.specificclick.net/?l=5381&sz=728x90&wr=j&t=j&u=http://tv.blogs.pressdemocrat.com/10859/bourdain-hits-streets-of-san-francisco/&r=http://www.pressdemocrat.com/&rnd=302624[/noparse]


    edit: I'm not sure how to capture the htm file as it's only on some page loads and nod32 is just blocking it randomly, it really needs to be figured out though, i've got about 100 of these so far today
     
  7. ittech

    ittech Registered Member

    Joined:
    Dec 5, 2007
    Posts:
    30
    Ok, I just noticed it's only my clients with 2.7 who are getting the HTML/IFrame.B.Gen Virus message, v 4.0 are getting the "Site blocked" message without a virus alert.

    Never deployed 3.x anywhere so not certain on that version.

    hxxp://afe.specificclick.net/?l=2309&sz=300x250&wr=h&t=h

    that link reports as a virus every single time with 2.7
     
  8. ittech

    ittech Registered Member

    Joined:
    Dec 5, 2007
    Posts:
    30
    i've just sent a sample password protected zip file in
     
  9. lolo2907

    lolo2907 Registered Member

    Joined:
    Apr 16, 2007
    Posts:
    13
    Still getting alerts as well. Have no idea when the new update is coming out. I know this is off topic but is anyone else fed up with ESET support? I would like to hear your experiences dealing with ESET direct support.
     
  10. tonytone

    tonytone Registered Member

    Joined:
    Aug 10, 2009
    Posts:
    1
    ESET NOD32 Antivirus - Alert
    Access denied !

    Details:

    Web page:
    h[I]tt[/I]p://afe2.specificclick.net/adserv/

    Description:
    Access to the web page was blocked by ESET NOD32 Antivirus.
    The web page is on the list of websites with potentially dangerous content
     

    Attached Files:

    Last edited by a moderator: Aug 10, 2009
  11. WhiskeyRiver

    WhiskeyRiver Registered Member

    Joined:
    Aug 10, 2009
    Posts:
    3
    Add WeatherUnderground.com as a victim. You have to get through three or four Nod32 HTML/Iframe.B.Gen warnings to get the weather. All related to specificclick.net.

    6:38PM Central time...
     
  12. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
    I'm not having any warnings using Wunderground.com. at 6:40pm central time.
     
  13. ccomputertek

    ccomputertek Registered Member

    Joined:
    Jul 27, 2009
    Posts:
    371
    I was not getting these when i tried it while using definitions i still had from yesterday.I just updated signatures right now and went to all links posted and am now getting the same warnings.
     
  14. WhiskeyRiver

    WhiskeyRiver Registered Member

    Joined:
    Aug 10, 2009
    Posts:
    3
    I'm using Nod32 v2.7 and v4323 signatures.... Still getting it.

    6:54 PM Central

    WR
     
  15. WhiskeyRiver

    WhiskeyRiver Registered Member

    Joined:
    Aug 10, 2009
    Posts:
    3
    UPDATE: 10:30PM August 10

    Just received signatures v3424. Everything back to normal now. Crisis appears over. :)
     
  16. lolo2907

    lolo2907 Registered Member

    Joined:
    Apr 16, 2007
    Posts:
    13
    I would really like to know why this occurred. Was this due to a 'bad' signature file or did ESET have a legitimate reason for blocking these ads? I have been hearing things, but I want to know what you think first.
     
  17. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    It was not a FP, but we've stopped blocking the url for now. This does not mean that it won't be blocked again if another piece of malware turns out to be related with the site.
     
  18. bradtech

    bradtech Guest

    Thanks Marcos I don't mind it being blocked however it sucks if it is unable to clean it off.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.