We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Avast detects infection, false positive?

Options
Wammer
Wammer Posts: 1,060 Forumite
Tenth Anniversary
Avast had detected a virus threat in Opera. I have received this warning message even after rebooting
Infection Details

URL: http://www.imageszoom.info/landing2. php
Process: C:%5CProgram Files%5COpera%5COpera.exe
Infection: HTML:Iframe-inf

I have run the url through a url checker. All the checking sites said it was OK apart from 3 which said it was a threat.

As I have a lot of tabs open in Opera, can someone tell me how to identify which tab is at fault? All the tabs are the ones I've had open for months, nothing new.

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    No, it's not a false positive. If you can't say which site is to blame, close all tabs.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    One of the redirections took me through a known RBN IP - 94.102.50.73 - ECATEL-AS AS29073. Ecatel currently top the Top 10 Bad Hosts list, 2013 - Q1

    Interestingly (or not), at the end of the redirections, I saw this:

    java_insecurexp.jpg

    http://www.java.com/en/download/faq/expire_date.xml
  • Wammer
    Wammer Posts: 1,060 Forumite
    Tenth Anniversary
    Thanks for that. I'm not 100% sure what it means, but guess that it's not good from what I did see.

    I have the latest Java installed v7U25, but have it disabled in all browsers apart from Firefox.

    I use all the tabs I have open in Opera so it's difficult to close them all.

    I'm probably way off the mark, but I have been looking at info on Amsterdam and see that that site is hosted in the Netherlands. Is that just a coincidence?
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Yes, it's just coincidence.

    One of the sites you have open in your tabs is serving up exploit code, which one exactly would be hard to tell.

    It mitigates any threat if your OS & programs are up to date.
  • Wammer
    Wammer Posts: 1,060 Forumite
    Tenth Anniversary
    Yes I keep everything up to date, eg monthly Windows Updates plus any extras, Adobe Flash, Avast. However I am using Opera v12.16 rather than the latest v15 as the new version is hideous. BTW v12.16 is the predecessor to v15 even though it doesn't sound like it.

    Is it possible that one of the sites I have been using on Opera for months has become infected recently?
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Yes, possible. It could also be external content - banner ad for example.
  • Wammer
    Wammer Posts: 1,060 Forumite
    Tenth Anniversary
    Yes that's what I was thinking, that it could be a banner ad, but so many sites have them that it's impossible to pinpoint.
  • Wammer
    Wammer Posts: 1,060 Forumite
    Tenth Anniversary
    I've identified the site / tab that is at fault. It was the one I was on when I first got the warning pop up.

    The site has actually posted that they have been advised of a dodgy ad and that "any attempts to block it have failed". That was 2 days ago.

    Thanks for your help.
  • forgotmyname
    forgotmyname Posts: 32,922 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    The problem is a site will sell a space on its page and someone buys that space and then sells it to several others.

    The main site may have no idea who or what is being advertised. Dodgy people rent a slot and then try to run malicious code in the advert.

    Clever and annoying at the same time.
    Censorship Reigns Supreme in Troll City...

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Wammer wrote: »
    I've identified the site / tab that is at fault.

    Can you PM me the url?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.