Malicious Software Warning

Status
Not open for further replies.

SteveColes

New User
Steve
Clear Safari's cache, would not be surprised if this is a leftover.
Probably not related, but this morning I find that when I attempt to go to page 2 of this thread, it switches momentarily, then jumps back to page 1. Only way I can get to page 2 is to select one of the items from the thread diagram.

Related??:icon_scra
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10

Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
 

SteveColes

New User
Steve
That's what I thought too, but I tracked the final target site to a hidden machine in china. They were using a dynamic DNS provider to hide their identity. The AV sigs were tripping on the URL which was a known bad site.
The most probable cause of your AV warnings was likely a poorly chosen virus signature by either your chosen AV provider, or the central clearinghouse of AV signatures (a resource subscribed to by nearly all AV vendors).

Over the past couple of years I have witnessed a number of instances where AV signatures were generated against code snippets from the MSDN (Microsoft Developers Network) and related sources. These code snippets and sample routines are used by many software developers.
Unfortunately, they are more likely to appear in legitimate code than illegitmate. But, since exploit developers also have access to these same resources, they occassionaly cut and paste these code samples into their exploits.

Then someone reports the exploit to an antivirus vendor, who then incorrectly latches onto the sample code when they create their AV signature and ... presto ... legitimate software starts getting flagged as a virus or other exploit.

In recent years I have had my accounting software partially wiped out by antivirus software for the same reason. I have also had a number of Microsoft Resource Kit utilities wrongfully flagged as exploits by AV software as well -- all due to poorly chosen AV signatures... even Yahoo Messenger is actively flagged as a keylogger by some AV vendors.

Sometimes these issues will resolve themselves if the AV vendors catch onto the mistake and rescind the signature, other times the only action you can take is to exempt that particular item from AV scanning by using your AV softwares provisions for user-defined exceptions.

Good luck!

Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET CLR 1.1.4322; OfficeLiveConnector.1.4; OfficeLivePatch.1.3)

Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
 

RayH

New User
Ray
Steve,

Thanks, but the problem is still there. Just a curiosity. Some day I'll figure out this Mac.:icon_scra

Ray
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10
 

sapwood

New User
Roger
:notworthy::notworthy::notworthy: We are so lucky to have such a wonderful technical team!

Thanks to 'da Bas, da Frog, and Papa Smurf :icon_thum

And apologies to anyone I may have left out :embaresse

Roger Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.4; en-US; rv:1.9.1.8) Gecko/20100202 Firefox/3.5.8
 

SteveColes

New User
Steve
Thanks to 'da Bas, da Frog, and Papa Smurf
Roger Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.4; en-US; rv:1.9.1.8) Gecko/20100202 Firefox/3.5.8
I had no hand in this. the technical team has no need of my help, they've been doing the job. I just commented on what I could see on my machine. Those are the guys who diagnosed and fixed the problem.
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
 
Status
Not open for further replies.

Premier Sponsor

Our Sponsors

LATEST FOR SALE LISTINGS

Top