That is strange as shit. Thank you for that though! That at least gives us some insight into how we might fix this. Might need to switch domain names.
There's actually a trojan script detected there. More info here:
You must be registered to see the links
In case I only disable web protection (the filter that blocks dangerous websites where malware has been detected by other ESET users), then one of the files that Firefox is trying to download into its cache gets blocked by the real time file scanner of the AV and gives this info about a trojan being downloaded.
More info (including file hash of the detected file) from the log:
Code:
<?xml version="1.0" encoding="utf-8" ?>
<ESET>
<LOG>
<RECORD>
<COLUMN NAME="Time">09.06.2018 0:23:27</COLUMN>
<COLUMN NAME="Scanner">Real-time file system protection</COLUMN>
<COLUMN NAME="Object type">file</COLUMN>
<COLUMN NAME="Object">xxx\Mozilla\Firefox\Profiles\xxx\cache2\entries\05A1193E7A11E4ADE86DEC49BE4D4E8EB1F93A0B</COLUMN>
<COLUMN NAME="Threat">HTML/ScrInject.B trojan</COLUMN>
<COLUMN NAME="Action">deleted</COLUMN>
<COLUMN NAME="User">xxx</COLUMN>
<COLUMN NAME="Information">Event occurred on a new file created by the application: C:\Program Files (x86)\Mozilla Firefox\firefox.exe (77DD8A387F34DCB0B8C164EC5F2978F7ADF1FBA2).</COLUMN>
<COLUMN NAME="Hash">04C7C34871952FB90B8D56B0F48734A642F43100</COLUMN>
<COLUMN NAME="First seen here">09.06.2018 0:12:46</COLUMN>
</RECORD>
</LOG>
</ESET>
Looks like there could be a trojan injected into your site. ESET actually has been giving warnings about this on your site for months.
Totally could be a false positive also.
_______________________
after some digging:
Yep, if this isn't a textbook case of a false positive, then... whatever. :biggrin:
Just look at the virustotal scan of this file:
You must be registered to see the links
Virustotal's site scan shows the same:
You must be registered to see the links
Only ESET doesn't like it. And this has been going on for months, half a year probably. You should contact them about this bullshit.
ESET is generally a decent AV, I've been using it for more than a decade. This is one of the rare cases.