Kaspersky and csshover.htc Possible False Positive?

| 6 Comments | No TrackBacks

This morning Kaspersky is detecting Downloader.JS.Iframe.aqo in csshover.htc on a few different websites.

Seems to be a false positive.

Virustotal shows the following:

File csshover.htc received on 04.09.2009 17:40:35 (CET)
AntivirusVersionLast UpdateResult
a-squared4.0.0.1012009.04.09-
AhnLab-V35.0.0.22009.04.09-
AntiVir7.9.0.1382009.04.09-
Antiy-AVL2.0.3.12009.04.09-
Authentium5.1.2.42009.04.08-
Avast4.8.1335.02009.04.09-
AVG8.5.0.2852009.04.09-
BitDefender7.22009.04.09-
CAT-QuickHeal10.002009.04.09-
ClamAV0.94.12009.04.09-
Comodo11072009.04.09-
DrWeb4.44.0.091702009.04.09-
eSafe7.0.17.02009.04.07-
eTrust-Vet31.6.64472009.04.09-
F-Prot4.4.4.562009.04.08-
F-Secure8.0.14470.02009.04.09Trojan-Downloader.JS.Iframe.aqo
Fortinet3.117.0.02009.04.09-
GData192009.04.09-
IkarusT3.1.1.49.02009.04.09-
K7AntiVirus7.10.6972009.04.08-
Kaspersky7.0.0.1252009.04.09Trojan-Downloader.JS.Iframe.aqo
McAfee55782009.04.08-
McAfee+Artemis55782009.04.08-
McAfee-GW-Edition6.7.62009.04.09-
Microsoft1.45022009.04.09-
NOD3239972009.04.09-
Norman6.00.062009.04.09-
nProtect2009.1.8.02009.04.09-
Panda10.0.0.142009.04.09-
PCTools4.4.2.02009.04.08-
Prevx1V22009.04.09-
Rising21.24.32.002009.04.09-
Sophos4.40.02009.04.09-
Sunbelt3.2.1858.22009.04.09-
Symantec1.4.4.122009.04.09-
TheHacker6.3.4.0.3052009.04.09-
TrendMicro8.700.0.10042009.04.09-
VBA323.12.10.22009.04.09-
ViRobot2009.4.7.16862009.04.09-
VirusBuster4.6.5.02009.04.09-
 
Additional information
File size: 4314 bytes
MD5...: 4d50942ad963dd3d0cde4fe42ae1157b
SHA1..: ddb47d9f8d783f8ff1b79527b65ee7e6ac53a359
SHA256: afb97a5d637531616f85cffcd11dd68e7b85f2b5aa01b51b7959dbf2fcf8704c
SHA512: c829e90f6a3669320aec4bb489fb91aa39ed17a85f1584156b5eb8fc32c26b4d
610ede9a8060ce5a82b945930796c7033c55a8e48e7c13a4a179d2aa41b459c0
ssdeep: 96:D+5yu5ugQhnmLzuAX6mLJ3FFD6wB5XhY/l1yYmLXiuiXqwCDGqh:Dju5ugQOF
zLJ3FF5B5S/l1B8XiuiXtCP
PEiD..: -
TrID..: File type identification
Unknown!
PEInfo: -
RDS...: NSRL Reference Data Set
-

UPDATEThis afternoon, I reported the false positive to Kaspersky via a webform. I heard back pretty quickly that this was fixed in the latest defs. Also note Ryan's entry in the comments.

My problem was compounded a bit becasue the BlueCoat cached the "infected" status, so I needed to clear the cache of that, before csshover.htc could be served.

No TrackBacks

TrackBack URL: http://www.infosecblog.org/mt-tb20071121.pl/881

6 Comments

got a few calls from clients about this today. Appears to be fresh. Hopefully will be fixed in the next round of definitions?

Hello Roger, this is now fixed. Apologies are in order.

_ryan
(I work as a security evangelist for Kaspersky)

We are receiving complaints about this as well.

I have checked the script in question on our server and it is intact, so this is definitely a false positive.

ZoneAlarm Internet Security Suite 7.0.xxx and ZoneAlarm Antivirus uses Kaspersky code and is detecting it as Trojan-Downloader.JS.Iframe.aqo
Kaspersky emailed me that the next set of definitions should correct the false alarm.

What a relief, we were planning to delete csshover.htc and a new hover menu.

My website was also hacked on 9th April, also with iframe worm to chinese server. But my www.hackalert24.com account informed me in time, to restore a backup from previous day, so i had no extensive downtime. Really recommendable this service!

Leave a comment

Archives

Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla
Powered by Movable Type 4.31-en

About this Entry

This page contains a single entry by Roger published on April 9, 2009 11:04 AM.

Java Runtime Environment 6.0 Update 13 was the previous entry in this blog.

SmartDraw and Office 2007 is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.