VIRUS ALERT: Is it Google or MS Security Essentials ?

by EO 15. February 2012 07:48

UPDATE: As my guess , this issue was reported by Microsoft as False Possitive! Still interesting to read.

Virus Alert, by Microsoft Security Essentials, I am not really sure what is going on. One of the End Users in the office called me and asked for Help. Every time he goes to “Google” , his security essentials was warning him, “Potential Threat Detected”

Looked carefully, yes it was true.

All what he was doing is

www.google.com and guess what!

clip_image002[5]

Now look carefully.

image

I fully scanned the computer with a up to date offline scanner, nothing was wrong, for testing I went to my PC and had the same result, remotely connected home and again same result.

Was it Google or Microsoft Security Essentials?

MS Security Essentials is warning us that Google is hosting a possible “exploid JS/Blacole.BW”. Based on my investigations this looks like a FALSE POSSITIVE alert.

image

There was no issue when I went to my favourite search engine, also other search engines, but Google.  From what I can investigate Google looks harmless.

clip_image002

Not just www.google.com also www.google.com.au , www.google.com.tr or even www.google.de gets  the same alert from, Security Essentials , WARNING “ Exploit:JS/Blacole.BW “

I have still no details about it but will keep an eye on it.

Anybody else having the issue, then please e-mail me Winking smile

Again its most likely a False Positive Alert but

Be careful

UPDATE: ( 4 hours later from this post Microsoft relased an update)

Alert level 

Exploit:JS/Blacole.BW


 

Summary

On February 14, 2012, an incorrect detection for Exploit:JS/Blacole.BW was introduced. On February 14, 2012, Microsoft released an update that addresses the issue. Signature versions 1.119.1988.0 and higher include this update.



Technical Information (Analysis)

On February 14, 2012, an incorrect detection for Exploit:JS/Blacole.BW was introduced. On February 14, 2012, Microsoft released an update that addresses the issue. Signature versions 1.119.1988.0 and higher include this update.

Tags: , , ,

Security

Comments (2) -

Matthias R. Wiora
Matthias R. Wiora Germany
2/15/2012 8:36:58 AM #

blog.cryptonic.net/.../...blacolebw-microsoft.html
Same issue =)

Cliff
Cliff United States
2/15/2012 9:36:13 AM #

I discovered the answer on this blog, it is a false positive:
blog.lan-tech.ca/.../

Add comment

  Country flag

biuquote
  • Comment
  • Preview
Loading

Welcome...

Welcome to my personal blog. In this blog you will have access to my Technical Articles which will be about Microsoft technologies specially Windows ( Windows 7 , 8 & Windows Server 2008 R2 , 8) . Security, will be also covered in depth, from Ethical Hacking to Penetration Testing

 

 

Month List