Old 01-11-2012, 01:48 PM   #1 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default w3.org Spam?

I'm getting a huge volume of blocks from a machine trying to call out to w3.org every 1-2 minutes. I've checked the IP and it is listed with w3.org. The filter is putting it in the Spam category. I've done virus scans as well as scanned with Malware Bytes and Super Anti-Spyware. All come up with nothing.

Has anyone else experienced this?
hs-admin is offline  
Old 01-12-2012, 12:40 PM   #2 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default

Finally solved. Like suspected it was a virus of sorts. Removed with Panda AV.
hs-admin is offline  
Old 01-12-2012, 01:04 PM   #3 (permalink)
Master Untangler
 
f1assistance's Avatar
 
Join Date: Apr 2009
Location: Holly Springs, NC
URLs submitted: 154
Posts: 218
f1assistance is on a distinguished road
Default

Quote:
Originally Posted by hs-admin View Post
Finally solved. Like suspected it was a virus of sorts. Removed with Panda AV.
Please do tell...it sounds like you used several tools in your bag of tricks. Did you use Panda's online scanner?
__________________
Untangle...because nothing is worse than doing nothing!
-------
2, Pentium (R) Dual-Core CPU E5300 @ 2.60GHz 2599.968, 2089.96MB RAM
f1assistance is offline  
Old 01-13-2012, 07:07 PM   #4 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default

Well I thought this was solved but looking at the logs again this afternoon its doing it again. Its very sequential in its attempts. I included a sample of whats coming up in the Even Log.
Anyone have a suggestion? False positive?

2012-01-12 8:24:35 pm
172.16.4.8
www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
true
true
in Categories Block list
Spam
128.30.52.37

2012-01-12 8:23:30 pm
172.16.4.8
www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
true
true
in Categories Block list
Spam
128.30.52.37

2012-01-12 8:21:36 pm
172.16.4.8
www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
true
true
in Categories Block list
Spam
128.30.52.37

2012-01-12 8:19:37 pm
172.16.4.8
www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
true
true
in Categories Block list
Spam
128.30.52.37
hs-admin is offline  
Old 01-13-2012, 07:11 PM   #5 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default

This is the output from zvelo.com's "test-a-site" service:

w3.org Technology (General), Advocacy Groups & Trade Associations No Known Risk zvelodb-v3

www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd Spam Possible Risk zvelodb-v3
hs-admin is offline  
Old 01-13-2012, 08:11 PM   #6 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,614
dmorris is on a distinguished road
Default

Try flushing the categorization cache in Web Filter, and then in your browser and then hitting that URL.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is online now  
Old 01-13-2012, 08:23 PM   #7 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default

Thanks for the reply, I emptied the filter cache. Is the browser cache empty and hitting the URL to be done on the problematic machine?
hs-admin is offline  
Old 01-13-2012, 08:35 PM   #8 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,614
dmorris is on a distinguished road
Default

Quote:
Originally Posted by hs-admin View Post
Thanks for the reply, I emptied the filter cache. Is the browser cache empty and hitting the URL to be done on the problematic machine?
Any machine behind Untangle should be fine. Are you just testing? What are you trying to do?
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is online now  
Old 01-13-2012, 08:42 PM   #9 (permalink)
Untangler
 
Join Date: Oct 2009
Location: N. AZ
Posts: 66
hs-admin is on a distinguished road
Default

I'm currently off site at the moment. I thought I had this solved earlier and happened to check again and the machine is still acting up.
I'm trying to figure out why it is calling w3.org in 1 and 2 minute intervals (roughly) which web filter is then categorizing and blocking as Spam. I have 1k+ blocks on it from the day, sort of filling up my event viewer. I thought at first of malware/spyware infection but all the scanners I've had the owner (non school owned laptop) run have come up with little or nothing.
hs-admin is offline  
Old 01-13-2012, 08:45 PM   #10 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,614
dmorris is on a distinguished road
Default

Quote:
Originally Posted by hs-admin View Post
I'm currently off site at the moment. I thought I had this solved earlier and happened to check again and the machine is still acting up.
I'm trying to figure out why it is calling w3.org in 1 and 2 minute intervals (roughly) which web filter is then categorizing and blocking as Spam. I have 1k+ blocks on it from the day, sort of filling up my event viewer. I thought at first of malware/spyware infection but all the scanners I've had the owner (non school owned laptop) run have come up with little or nothing.
Oh, well I'd just flush your category cache. It doesn't sound like its categorized as Spam anymore so it probably just was the first time you checked. My guess was that it was a miscategorization at one point or something.

I wouldn't worry about that URL, many things references the w3.org DTDs and I don't think a client downloading that is any reason to be alarmed.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is online now  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:12 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2