Warnings from antivirus

Status
Not open for further replies.

RichardV

Vaping Master
ECF Veteran
Verified Member
Mar 26, 2012
4,523
9,394
72
The Golden Isles of Georgia, USA
On numerous threads I am getting Script-inf warnings from Avast. Not only in the threads below , just scattered randomly thru the forum.
Here is one of them
URLhxxp://www.e-cigarette-forum.com/forum/ask-vets-answers/621178-getting-petina-my-copper-mod.html|{gzip} InfectionHTML:Script-inf

another
URLhxxp://www.e-cigarette-forum.com/forum/ask-vets-answers/621225-anyone-here-using-smokjoy-gi2-able-keep-locked.html|{gzip} InfectionHTML:Script-inf
 

RichardV

Vaping Master
ECF Veteran
Verified Member
Mar 26, 2012
4,523
9,394
72
The Golden Isles of Georgia, USA
No ads showing. I only see avatar pics & a CASAA sig. I wonder if something on these particular threads might be causing a false positive warning from Avast.

I am now getting a blocked infection warning on this thread. No avatar or sig showing.
http://www.e-cigarette-forum.com/fo...-here-using-smokjoy-gi2-able-keep-locked.html

Infection blocked
URL
hxxp://radioskin.com/?f_PgUx=Y0n2HZfnI4__evM9l_ce_2Lesz5rawbLaq&ygF_N=_2_6G76qU4V6Ugfm0wY5Lfaxbr3N3t&3OW=R5T

Infection
URL:Mal
 
Last edited:

Shirtbloke

Super Member
ECF Veteran
Apr 26, 2014
966
957
UK
I was having problems accessing pages yesterday which Retired1 helped me out with.
I've since come to the conclusion that it's a browser hijacker that's causing the problems for me.
I'm currently running an Avast virus scan (87% complete at the moment but painfully slow) and it's found two infections so far.
I'll report back exactly what they are when the scan finishes.
 

retired1

Administrator
Admin
Supporting Member
ECF Veteran
Verified Member
Apr 5, 2013
50,732
45,041
Texas
No ads showing. I only see avatar pics & a CASAA sig. I wonder if something on these particular threads might be causing a false positive warning from Avast.

I am now getting a blocked infection warning on this thread. No avatar or sig showing.
http://www.e-cigarette-forum.com/fo...-here-using-smokjoy-gi2-able-keep-locked.html

Infection blocked
URL
hxxp://radioskin.com/?f_PgUx=Y0n2HZfnI4__evM9l_ce_2Lesz5rawbLaq&ygF_N=_2_6G76qU4V6Ugfm0wY5Lfaxbr3N3t&3OW=R5T

Infection
URL:Mal

Not seeing that url anywhere on ECF.

Going to reboot into Winderz and do some checking from that side of the notebook.
 

Shirtbloke

Super Member
ECF Veteran
Apr 26, 2014
966
957
UK
Right, the scans finished and it sounds like we've likely got the same problem.

Avast has found two files in the Local Settings/Temporary Internet files folder.
They're flagged up as Threat:HTML:Script-inf and their severity is High.

They're interestingly named.

colin-firth-wants-kings-speech-sequel-106269[1].txt
kristen-stewart-miss-out-snow-white-sequel-103492[1].txt

I've no idea where I got these from, I usually keep away from the dodgy parts of the internet, but the filenames sound like they could have come down an ad network.


So I'm to press the delete key and hope that's the end of it.
 

Shirtbloke

Super Member
ECF Veteran
Apr 26, 2014
966
957
UK
No ads showing. I only see avatar pics & a CASAA sig. I wonder if something on these particular threads might be causing a false positive warning from Avast.

I am now getting a blocked infection warning on this thread. No avatar or sig showing.
http://www.e-cigarette-forum.com/fo...-here-using-smokjoy-gi2-able-keep-locked.html

Infection blocked
URL
hxxp://radioskin.com/?f_PgUx=Y0n2HZfnI4__evM9l_ce_2Lesz5rawbLaq&ygF_N=_2_6G76qU4V6Ugfm0wY5Lfaxbr3N3t&3OW=R5T

Infection
URL:Mal

I was getting warnings from Avast to a radioskin url too.
 

rolygate

Vaping Master
Supporting Member
ECF Veteran
Verified Member
Sep 24, 2009
8,354
12,402
ECF Towers
I have Avast and it doesn't report any problem.

No other members are reporting this. On the very rare occasions when we had malware on the server in the past, a flood of members reported it and the reports kept coming until the issue was fixed.

So I think this will probably turn out to be a local issue. Maybe a rootkit. Perhaps the Malwarebytes rootkit removal tool may be useful here, worth a try anyway.
 
Status
Not open for further replies.

Users who are viewing this thread