Page 1 of 1

HTML/Framer Virus question

Posted: Wed Jun 16, 2010 10:05 am
by wvjohn
I went to a web site run by some friends...h##p://queenofheavencircle.org/ and my AVG webshield said that the page was infected by the HTML.Framer virus (and blocked it).


the details AVG gives me are:

Process name: C:\ProgramFiles\Mozilla Firefox\firefox.exe
Process ID: 2956


I did a little looking around it it seems to be a method for injecting code directing the pc to visit some funky website or something. Possibly the kind of code that can be placed on a website via SQL injection.

If it is real - I want to let them know so they can fix it, obviously. But I don't want to start a wild goose chase for them on a false positive.

any ideas?

I tried using Chrome and got two separate alerts on this.
From what I have been able to find, this was originally designed to exploit an Older IE exploit, but we all know how frequently these things are adjusted

Posted: Wed Jun 16, 2010 10:09 am
by eGoCeNTRoNiX
Avira doesn't seem to have a problem with the site.. May be a falst positive?

eGo

Posted: Wed Jun 16, 2010 10:19 am
by FlyingPenguin
Could have been a malicious ad banner, or possibly even a script you picked up on another site that was delayed. Or maybe it's a false positive. Is it consistent? Try clearing your cache and trying it again.

Google safe browsing says it's clean: http://www.google.com/safebrowsing/diag ... circle.org

Posted: Wed Jun 16, 2010 10:36 am
by wvjohn
Online Link Scan - Virus, Trojan, Adware and Malware Scanner

Scanning in progress. Be patient.

--------- LINK SCAN SUMMARY ---------
URL scanned: http://queenofheavencircle.org/
PhisTank say's: Service not available.
AVG say's: Service not available.
SiteTruth say's: This site is safe.
Google Safe Browsing say's: This site is safe.
Threat Name: No Threat FOUND
Threat Definitions: 799869
Engine Version: 0.96.1
Host IP: 65.182.100.166
Link Status: Clean
File Size: 1.63 KB
Time Finished: 5 secs
Overall result: This site is secure.

Cleared cache, still getting AVG block on this site...


http://www.avg.com.au/resources/web-page-scanner/

AVG online web scanner says it's clean.....lol