cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

As of 6/17/2017, 1:45 PM EST, every time I log in using the Ebay signin screen, my Norton AntiVirus software gives me a message it is blocking/removing a javascript file,  rriframe.flat.min[1].js . This file is labeled a Trojan. Gen.NPE.2 by Norton. I have tried clearing my cache, cookies, etc, to no avail. I did call Ebay, but they have not heard of any problems other than mine. Does anyone have any information or advice. Thanks. Phil.

Message 1 of 22
latest reply
21 REPLIES 21

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

AN UPDATE AS OF 8:31 PM:

After research I finally downloaded Chrome and used Chrome for my Ebay sign in. No problems, at least not yet. The browser I was using was Edge, from Microsoft, Windows 10. Does this make sense? Has anyway else experienced anything like this? I would appreciate any insights. Phil.

Message 2 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Sounds like a new variant of what was happening recently with what I BELIEVE were false positive detections by AVG and Avast due to eBay use of heavily obfuscated anti-bot signin scripts that trigger the false detects. This time it's rriframe.flat.min.js triggering the detect instead of rrbundle.flat.min.js (both are present and HEAVILY obfuscated which is something AV suites trigger on as suspicious behavior).

 

Read my posts in this thread: https://community.ebay.com/t5/Selling/Are-AVG-Users-getting-notice-of-REDIRECTOR-BKG-Trojan-Virus-Fr...

 

Did your Norton AV update virus definitions or program files overnight just before the problem started?

If so, that can indicate one of two things: Norton discovered something in the wild and is flagging on it, or Norton changed something in the heuristics/definitions that causes the false detect of non-specific threats.

 

I believe the latter is more likely. It happens all the time.

 

Here is the text of another post of mine from the PS forum:

in reply to xxxxxxxxx 06-06-2018 03:55:12 PM
berserkerplanet
Observation: in all the threads on the boards recently about this issue where the poster
provides any details, it is only AVG and Avast doing this - and both have a long history
of false positives.

Haven't seen anything about any of the 100+ other virus/malware suites* detecting that
or anything on eBay.

*Windows Defender, McAfee, Symantec, Sophos, Kaspersky, ESET, Avira, BitDefender,
F-Secure, Comodo, F-Prot,... or in browser site blacklisting in Firefox and others
(via Google Safebrowsing?)
VirusTotal.com isn't what it used to be (many big names no longer there), and because of
possible login issues, difficult to say if results of URL scans are valid, but it shows 68
out of 68 "no detection" for the URL ( https://www.ebay.com/rdr/js/s/rrbundle.flat.min.js )
in the AVG screenshot in post 5 or any other URL I threw at it (signin.ebay.com,
https://www.ebay.com/sh/ovw, whatever)
If someone runs into a detection by AVG or Avast or whatever virus suite, try scanning
the URLS at VirusTotal (either the one the virus suite is specifically warning, or the
URL for the link clicked that causes the warning) and see if anything at VirusTotal agrees
with your AVG or Avast.
Can also try using Google Safebrowsing directly to see what Google thinks: https://www.google.com/safebrowsing/diagnostic?site=WEBSITE_URL where you replace WEBSITE_URL with your suspect URL ie:
https://www.google.com/safebrowsing/diagnostic?
site=https://www.ebay.com/rdr/js/s/rrbundle.flat.min.... or https://www.google.com/safebrowsing/diagnostic?site=https://signin.ebay.com (note that Google scans may not be real-time or even close - I'm guessing they don't scan
assumed secure sites like eBay or Bank of America as often, and focus their efforts on
the other more risky sites - likely those that pop up in a lot current popular searches) or check it directly here: https://transparencyreport.google.com/safe-browsing/search Also: https://www.urlvoid.com/ https://sitecheck.sucuri.net

 

 

 

Recap/Summary:

I believe these are all false detects of obfuscated JavaScript files eBay is using as part of an anti-bot login protection framework called "RoboRadar". The AV suites are freaking out over the obfuscated nature of the files (they score that as generally suspicious behavior), throw up their own variety of a generic trojan warning, and block access to it. Nothing else detects anything wrong with the JS files, which reinforces that belief.

 

It is possible to use Adblock, AdblockPlus, etc to block those JS files and prevent the AV warnings without any collateral damage (not being able to log in or any security issues) with a general rule of the form:   ebay.com/rdr/*$domain=signin.ebay.com

 

 

Message 3 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

beserkerplanet :  Thanks so much for your detailed reply! I really appreciate it!

There is much here to research and investigate and learn.  Though I worked as a programmer for 20+ years between 1985 - 2006, there is much here that is new to me. It all is interesting, and in a way, reassuring. At this point (and I have a good ways to go in my research) I think your initial tentative conclusion, that this is probably a false alarm, is probably true.  I did do a complete Norton system scan earlier in the day, and I am sure Norton changed some things.

I am still wondering why I am not getting any warnings/blocks when I use my Chrome browser. I have checked and the so-called suspicious file is not on machine, at least not using standard MS search techniques. If you happen to pass by this post again, and could offer some insights on why Chrome seems ok, but Edge does not (according to Norton Anti-Virus software) I would again greatly appreciate it.

Either way, thanks so much for your insightful, helpful comments!

Phil Gennuso

Message 4 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

beserkerplanet:

Thanks so much for your postings. I really appreciate it!

There is alot here to review and research. I did work as a programmer for over twenty years, 1985-2006, but much of what you said is new to me. 

I tend to agree with your assessment - that this is probably a false warning, due to the reasons you brought up, but I will do further due diligence.

One issue that still puzzles me is that I don't have this problem when I use Chrome, only when I use Edge, the MS browser.  If you happen to pass by this board again and can offer some insight that would be very much appreciated.

Either way, thanks again so much for your thoughts! I would love to take a course on Udemy with you as the creator on this subject! If you ever decide to do so, or publish an ebook on this subject, please let me know.

Phil Gennuso

Message 5 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Hi all I have the same problem only with the edge broswer.  Starting on 6-18-18 No problems on Chrome or Firefox or Opera   My guess it is on ebays end as usual they are always working on things and when ever they work on one thing something else gets broke, never fails sorry for the inconvenience

Message 6 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

best-deals-fast-ship:

Hi, thanks so much for your comments.

I called Ebay yesterday when this started for me, they said they haven't heard anything, so this confirms the problem. I think the gentleman, beserkerplanet, has a great analysis, and I will use his comments to do some research on my own.

I will let you know if I find anything else out.

Phil Gennuso

Message 7 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Yeah well just remember this every other place I logged into with a password works perfect when I sign in with microsoft edge, try it for yourself and you will see it is ebay.  The proof is on the pudding.  

Message 8 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

>>Thanks so much for your postings. I really appreciate it!

You are very welcome.

You wouldn't find the file on your machine - Norton blocked it.

As to why no warning using Chrome: only reason I can think of is that it isn't called when Chrome is used.


My guess is that eBay isn't dishing up the Roboradar stuff when it detects Chrome browser (via passed browser  user-agent) for whatever arcane reasons (really makes no sense to exclude Chrome since Roboradar is an anti-bot framework)

Anyway, the next step would be to determine if that is the case. I do not  (and will never) use Chrome, so no help here. If you can figure out how to get a look at the page components loading in Chrome (maybe with any built in web developer tools - network console?) you can see if anything pertaining to  Roboradar is loading when you visit  https://signin.ebay.com  with Chrome.

 

I could also use Adblock Plus to look at what loaded (and Adblock in Chrome could do same I believe.) Things like Smartsniff, Fiddler2, NetworkActivityMon, Wireshark, and other external to the browser packet sniffers are mostly useless since this is HTTPS encrypted traffic.

I use HttpFox in Firefox 31 (an old addon in an old Firefox version - my preference) to look at HTTP traffic in/out of the browser.

 

Here is a cropped* view of the browser window with HttpFox open in bottom of window showing the calls made:

 

ebay_roboradar_httpfox_snag_cropped_061818.gif

 

*cropped because my screen is 1920x1080, a full image is way too big to post here, and posting it reduced size makes it unreadable.

 

All the stuff loaded from https://www.ebay.com/rdr/... is the Roboradar stuff.

 

>>

Message 9 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Yes, I am having the same experience. Every other site seems to work fine when I sign in. No problems. So it looks like it is unique to Ebay. Evidently Ebay tries to download alot of javascript files which Norton Antivirus may have trouble figuring out. That is what I think it is. But I am learning so much with this experience and will have to keep researching. I was very busy today, did not get a chance to call Ebay, hopefully I can tomorrow. Edge is still giving me the same problems.

Thanks for all your information. Let me know if anything else turns up.

I will keep things current with this stream.

Phil

Message 10 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

I posted elsewhere yesterday or before. I find it curious I didnt have problems in Windows 10 or applications in my new computer until ebay started fiddling with their site more actively 2 days ago.

Microsoft claimed it was Malwherebytes upgrade blocking me which is possible but I couldnt get into outlook or any files last night- Once he removed MB it is working fine but I had found totally messed up pages on Ebay 2 nights ago in most parts of the site - going in and out, mostly out - missing graphics,

etc - didnt pick up any thing on virus scans etc. Frustration is now I am without Malwhere Bytes which I have to risk reinstalling just to double protect myself from Ebay ! I had reported it to Ebay

Message 11 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Thanks for your post. I have never used Malwherebytes, I have used Norton with decent results. Increasingly it seems that the problem is with Ebay. I am going to try to call them tomorrow and will update this stream with any new information. Phil.
Message 12 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

I will never use Norton again - too many problems with it - I have been on Eset now for 3 yrs so much better and also Malwarebites & now /Premium which didnt have a conflict with Norton which I did before. I also have Adblock which is a vast improvement but doesnt block all ads nor the cookie agreement pop ups.  I am not a techie so dont know the correct terminology but I may have had two separate issue/ events. But I have to believe that when you go on an unstable page of Ebay there is a risk, at at min, my computer cant easily read a format that is missing key components. I have been reporting a lot of weaknesses and errors to both the pc platform and the mobile - Each has many errors/ incorrect defaults which may or may not be deliberate. It feels to me there are many oversights and the left foot isnt talking to the right foot. When I was asked regarding what version of Ebay app I had due to inability to list and page advancement being clipped & shut down I had the most current version AHEAD of the version the rep said they had & I needed !! That says a lot... Both issues have since been cleared up on my pages but I really feel Ebay needs to be more transparent sharing  schedule repairs on the announcement board, just like any bank or other large company that does on their website. Since this is one of the largest 24 hr global interactive website with shopping cart there needs to be more attention given to the seriousness of site failure , site functionability vis a vis sellers entering into a contract & paying for a service & reasonable expectation and communication of same.  Common sense tells you it saves a lot of time for everyone  and for years I have been recommending a tech prob reporting area on site for users where you submit an issue and it could be processed much faster ! When rep said it existed it is only for certain things but not for tech which is frankly more important ! Not rocket science - many other websites have it - they are making it much more complicated than it needs to be - remove 50% of unnecessary stuff on the site, archive old posts, lighten the load and I guarantee  site would run much better !

Message 13 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

UPDATE JUNE 20, 2018, 6:16 PM EST:

Just wanted to give an update about this strange file, "rriframe.flat.min [1].js

 

I have called Ebay repeatedly to find out if this is there file, and they have yet to get back to me.

As of yesterday, Norton was still blocking this file from downloading from the Ebay signin screen using Edge.

 

Today, at 6:16 PM, I signed on to Ebay using Edge and Norton did not block anything. I closed the browser and searched my computer and sure enough found this file: "rriframe.flat.min [1].js" sitting in on of my temp directories. I deleted it just for good measure.

 

Evidently Norton now thinks this file is no longer dangerous. 

I think the hypothesis originally proposed by beserkerplanet is the correct one, but the way Ebay and Norton go about this is really quite sloppy in my opinion.

 

Tomorrow if I get a chance I will give Norton and call and see what they have to say.

 

I do appreciate all the input, it certainly has helped to figure out what has been going on and I certainly have learned a good deal. I am going to keep this stream open until I get a definitive answer if that is at all possible.

 

Best regards,

Phil Gennuso

Message 14 of 22
latest reply

Re: EBAY SIGNIN SCREEN CAUSING NORTON ANTIVIRUS TO BLOCK A JS FILE FROM DOWNLOADING (TROJAN VIRUS)

Thanks again for your expert advice. As of 6/20 Norton does not appear to be blocking this file, rriframe.flat.min[1].js. I used Edge, signed in, no pop up from Norton. When I checked my hard drive, sure enough, this file was sitting in a temporary directory. I just deleted it without any event.

 

I have trouble tickets submitted to Ebay and I will try to contact Norton to get any further information but I think your original hypothesis is probably right.

 

Phil

 

Message 15 of 22
latest reply