Help - Search - Members
Full Version: HEUR:Trojan-Downloader.Script.Generic on Yahoo mail
Kaspersky Lab Forum > English User Forum > Virus-related issues
Homi
Hi all

I just started to experience a problem accessing my yahoo email account. When ever i try to log-in my account kaspersky blocks n gives a following msg

The requested URL could not be retrieved

While trying to retrieve the URL:

http://aa.mc357.mail.yahoo.com/mc/
welcome?.gx=1&.tm=1254142397&.rand=
c31plihp0h9gb

The following threat was encountered:

The requested object is INFECTED with the following viruses: HEUR:Trojan-Downloader.Script.Generic
Generated:
28/09/2009 10:50:54 PM
Kaspersky Internet Security 2010


I looked in virus database and didn't find any results about this particular trozan.

Now I have no clue what is happening or what should I do. I have send an email to yahoo support about this issue but I am not sure if they are going to respond. So can any one help me to solve this issue?? Pls...
richbuff
Welcome. please send it to the Lab, instructions are located in the third important topic located near the top of the Virus section of this forum. And here: http://forum.kaspersky.com/index.php?showtopic=13881
Homi
QUOTE(richbuff @ 29.09.2009 08:37) *
Welcome. please send it to the Lab, instructions are located in the third important topic located near the top of the Virus section of this forum. And here: http://forum.kaspersky.com/index.php?showtopic=13881



I have sent the report. Now how long Can you please give a clue how long this process is going to take...?
Homi
QUOTE(Homi @ 29.09.2009 15:31) *
I have sent the report. Now how long Can you please give a clue how long this process is going to take...?



Ok I received email from Kaspersky labs and they said that no virus or malware was detected in the file... but i am still not able access my email.. any other suggestions???
emilyngai
Hi.
I have got a problem. When I logged in to my yahoo email, Kaspersky denied the process and showed a big red box. It said "HEUR: TROJAN-DOWNLOADER. SCRIPT. GENERIC".
Do you know what it means? I want to get back my mail box. What should I do??Please help me
dawgg
Send the link which is detected to newvirus@kaspersky.com
Make the subject of the email "false positive - HEUR: TROJAN-DOWNLOADER. SCRIPT. GENERIC"
In the main body of the email, write the website and that it pops up when you log into yahoo email.

Its a "heuristic" detection from Kaspersky - the detection you got implies Kaspersky is saying "its likley there is a malicious script on the website".

It may be a false-positive.


I cant reproduce the detection on my end when signing onto yahoo mail. Can you private message me the link which is detected please.
dawgg
I'm not getting that detection on my computer. Try to update Kaspersky and try again - does it still detect it?
Lorenzo Carlos
QUOTE(dawgg @ 1.10.2009 08:48) *
I'm not getting that detection on my computer. Try to update Kaspersky and try again - does it still detect it?


I am getting the exact same problem, it started today.

can anyone help me?

thanks
Homi
QUOTE(Lorenzo Carlos @ 2.10.2009 10:50) *
I am getting the exact same problem, it started today.

can anyone help me?

thanks



dude... u need to contact yahoo mail support too... now that error is fixed for me .... yahoo replied to me in 2 days n my mail account was fixed.... i dont know how exactly it got fixed... good luck man!!
jarchack
I'm getting the same thing on yahoo and digg both with firefox and chrome. If I clear the kaspersky logs and the internet cache it will stop for a day or 2 then come back up.
dawgg
QUOTE(jarchack @ 3.11.2009 13:01) *
I'm getting the same thing on yahoo and digg both with firefox and chrome. If I clear the kaspersky logs and the internet cache it will stop for a day or 2 then come back up.

In when Kaspersky gives you that popup, make note of the link and click Allow, when the page is loaded, pause Kaspersky, click File - SavePageAs (Firefox method) and save it to your desktop.

Compress the file into a zip or rar archive and upload it to a file-hosting website such as http://rapidshare.de/
Private Message me the download link to the file and the web-link which was detected.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.