Jump to content

Revive Adserver v3.2.4 and Kaspersky reporting Trojan?


bizi10

Recommended Posts

Does anyone else have a problem with Kaspersky Total Security? I got informed that it reports our ads zones as some kind of Trojan but I didn't find anything wrong at our ads server.

We have the latest Revive Adserver v3.2.4 the site that displays ads is www.racunalniske-novice.com

Any thoughts on whats wrong? Is Kaspersky reporting a false positive?

A few errors reported by Kaspersky:

23.08.2016 21.14.18    Download blocked   http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=21&cb=INSERT_RANDOM_NUMBER_HERE  Object name: HEUR:Trojan.Script.Generic    Object: http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=21&cb=INSERT_RANDOM_NUMBER_HERE  Application: Internet Explorer    Object type: Trojan program    Time: 8/23/2016 9:14 PM
23.08.2016 21.14.18    Object (file) detected   http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=21&cb=INSERT_RANDOM_NUMBER_HERE  Object name: HEUR:Trojan.Script.Generic    Object: http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=21&cb=INSERT_RANDOM_NUMBER_HERE  Application: Internet Explorer    Object type: Trojan program    Time: 8/23/2016 9:14 PM
23.08.2016 21.14.18    Download blocked   http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=29&cb=INSERT_RANDOM_NUMBER_HERE  Object name: HEUR:Trojan.Script.Generic    Object: http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=29&cb=INSERT_RANDOM_NUMBER_HERE  Application: Internet Explorer    Object type: Trojan program    Time: 8/23/2016 9:14 PM
23.08.2016 21.14.18    Object (file) detected   http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=29&cb=INSERT_RANDOM_NUMBER_HERE  Object name: HEUR:Trojan.Script.Generic    Object: http://ads.racunalniske-novice.com/openx/www/delivery/afr.php?zoneid=29&cb=INSERT_RANDOM_NUMBER_HERE  Application: Internet Explorer    Object type: Trojan program    Time: 8/23/2016 9:14 PM

And an image of the reported errors. But it doesn't even get to the banner id. Is it blocking the normal invocation script?

Kaspersky.JPG

Thanks for any help you can give me.

Link to comment
Share on other sites

1 minute ago, Erik Geurts said:

Either the scanner has a false positive or your own installation of Revive Adserver was compromised. 

Well yeah I figured out that too. :) But how to tell if it's the first or the second option? Can someone else check with free trial of Kaspersky Total Security on his Revive installation?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...