Welcome, Guest. Please login or register.
January 03, 2010, 10:00:44 PM

Login with username, password and session length

347294 Posts
38413 Topics
87296 Members

Latest Member: catmee 36

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Trojan in my own blog or a False Positive?
« previous next »
Pages: [1] Go Down Print
Author Topic: Trojan in my own blog or a False Positive?  (Read 1092 times)
skynet71
Newbie
*
Offline Offline

Posts: 2


« on: September 24, 2009, 09:52:28 AM »

Hi everyone. Comodo keeps detecting a trojan in my own blog, could it be a false positive? Maybe from a javascript widget? The Comodo only detect it when I open my blog with the IE8, with firefox everything is ok  Huh. Can anyone help me please?

My blog is hxxp://fossaceptica.blogspot.com

And here is the Comodo log:
C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2S5MJXV0\TyntLite[1].js

TrojWare.JS.TrojanDownloader.Iframe.boi[at]42770545

Edit:
I case it is bad i disabled the link to prevent direct infection !!
« Last Edit: September 24, 2009, 03:50:03 PM by Ronny » Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1529


« Reply #1 on: September 24, 2009, 03:02:56 PM »

You can submit the file to VirusTotal and see what it thinks.

If you feel it's a false positive, you should also submit the file to Comodo Malware Analysis so they can check it out and they'll add it to the whitelist if it is in fact a FP.
Logged

Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5363



« Reply #2 on: September 24, 2009, 03:51:22 PM »

Site inspector reports it as malicous... so I'd be carefull with this...
Logged

Forum Volunteer - Any concerns? Please send me a PM and/or review the Forum Policy !
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1706


The only thing i ask for are eggs.


WWW
« Reply #3 on: September 24, 2009, 04:05:12 PM »

Only Comodo detects it.

http://www.virustotal.com/analisis/8b31c71af532b3789df92f73eb0a10169f13e101b30f60b8446f0f4b2c53fcd4-1253825749

But since Site Inspector says its malicous, i would say its bad and not a FP.

We need a "What to do if your website is infected" thread. Grin
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
skynet71
Newbie
*
Offline Offline

Posts: 2


« Reply #4 on: September 25, 2009, 04:22:58 AM »

Hi, thank you for the help.

I've disable the widgets one by one to see if the problem was with those, and finally traced it back to the stats widget from http://whos.amung.us/.

In fact I search it in Google and find out that there are a lot of people complaining about the same thing (http://wordpress.org/support/topic/304563), wich is odd, since whos.amung.us its a very well known widget among bloggers, and the problem is reported only by some antivirus. Any way, trojan or not, I've change the widget to its non javascript version and everything its ok now, I didn´t want to scare off my readers  Undecided

Thank you everyone, and sorry for the really bad english, i'm not use the write it  Tongue
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5363



« Reply #5 on: September 25, 2009, 05:29:14 AM »

 Thumb Up well done, and no problem on the English it's good.
Logged

Forum Volunteer - Any concerns? Please send me a PM and/or review the Forum Policy !
Tags: trojan 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.066 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com