Avast WEBforum

Other => Viruses and worms => Topic started by: clsiburt on August 04, 2013, 05:36:12 PM

Title: Website shows infected with JS:HideMe-B [Trj]
Post by: clsiburt on August 04, 2013, 05:36:12 PM
I have tried to go to the website for a local concert venue and Avast has alerted me that it is infected with JS:HideMe-B [Trj].  I did some searching here and found that I should check a few sites to confirm infection.  None of those other sites show it as infected, just Avast.  Is this a false positive or are the other sites wrong?


hxxp://centennialterrace.org is the site in question.

http://sitecheck.sucuri.net/results/centennialterrace.org shows clean and not blacklisted.

http://www.UnmaskParasites.com/security-report/?page=centennialterrace.org also listed as safe.

Anyone have any thoughts here?

Thanks,
Chris
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Secondmineboy on August 04, 2013, 05:50:01 PM
Hello Chris,

i looked up some sites either and it looks safe to me.

Here you can the results for many website check sites: http://ScanURL.net/?u=centennialterrace.org#results

For some you have to copy the URL into a box or a field and then click scan.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Secondmineboy on August 04, 2013, 05:51:44 PM
You can report a false positive over this site here: http://www.avast.com/contact-form.php

Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: clsiburt on August 04, 2013, 06:21:24 PM
Thanks!  I will try reporting it and see what happens.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on August 04, 2013, 06:59:33 PM
Various malware reported for same IP: http://support.clean-mx.de/clean-mx/viruses.php?as=AS31815&sort=email%20asc&response=alive
indicator obfuscation possible for  JCEMediaBox....update to JCE 2.3.2. please or report to twitvid.com/player/

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mike c on August 05, 2013, 08:39:32 PM
Hi,

I have experienced the same issue, same error/infection from Avast, relating to this site hxxp://www.graceniagara.ca

These two scans look clean,
http://sitecheck.sucuri.net/results/graceniagara.ca
http://www.unmaskparasites.com/security-report/?page=graceniagara.ca

I have already reported it to Avast (yesterday), I haven't heard back yet.

Thanks for any help.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Lain SE on August 05, 2013, 10:04:51 PM
PLEASE, help me...My site is CLEAN, but Avast has alerted me that it is infected with JS:HideMe-B [Trj]...

How can i fix it??

I have already reported it to Avast, but nothing yet...  :(



Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: HonzaZ on August 06, 2013, 10:03:52 AM
Hi all,

JS:HideMe-B is triggered when seeing this piece of code:

Code: [Select]
<div id='hideMe'>components inside recipe ingredients referred to as lifestyle Daily cia lis pill <a href="hxxp://sotrueradio .org/">Cia lis without prescription, canada</a> </div><script type='text/javascript'>if(document.getElementById('hideMe') != null){document.getElementById('hideMe').style.visibility = 'hidden';document.getElementById('hideMe').style.display = 'none';}</script>
Of course the exact ad may vary, but this is the template.

From my experience, this is most often appended right after <body> tag.

Honza Zíka
avast viruslab
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mike c on August 06, 2013, 02:32:15 PM
Hi all,

JS:HideMe-B is triggered when seeing this piece of code:

Code: [Select]
<div id='hideMe'>components inside recipe ingredients referred to as lifestyle Daily cia lis pill <a href="hxxp://sotrueradio .org/">Cia lis without prescription, canada</a> </div><script type='text/javascript'>if(document.getElementById('hideMe') != null){document.getElementById('hideMe').style.visibility = 'hidden';document.getElementById('hideMe').style.display = 'none';}</script>
Of course the exact ad may vary, but this is the template.

From my experience, this is most often appended right after <body> tag.

Honza Zíka
avast viruslab



Thank you for that... I did find that in my site. I removed it.

How do I get access back to the site now since Avast is still blocking it? Is there some "unblock" feature, I can't find one.

Thanks
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: HonzaZ on August 06, 2013, 03:34:55 PM
When we are talking about ScriptShield, there is no database of URLs. If avast cannot see the signature, it does not raise popup message. Maybe you still have the infected version in browser cache?
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: jbates on August 06, 2013, 07:46:36 PM
When I visit my work's main page http://yumalibrary.org/public (http://yumalibrary.org/public) I get the same thing. I searched for the <div id='hideMe'> in the code, but can't find it. What gives?
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: HonzaZ on August 07, 2013, 09:17:19 AM
When I wget your page (yumalibrary.org/public), I can see it:

Code: [Select]
<div id='hideMe'><p>The drugs also treat..........................Buy branded vi a gr a</a> .</p></div>
<script type='text/javascript'>
if(document.getElementById('hideMe') != null){
document.getElementById('hideMe').style.visibility = 'hidden';
document.getElementById('hideMe').style.display = 'none';
}
</script>

Keep in mind that this code does not have to be on the server in plain text, but if you use any server-side scripting, such as PHP, it can be inserted via some obfuscation (base64, gzinflate, rot13, ...).
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Daffy on August 17, 2013, 05:33:17 PM
Same with my works website.
Kfum-mus.dk

And now we cant enter it. Pls fix this
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Secondmineboy on August 17, 2013, 06:09:29 PM
Hello Daffy,

you can report this as a false positive ofer this form here: http://www.avast.com/contact-form.php
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: !Donovan on August 17, 2013, 06:25:01 PM
Please follow the instructions given in previous posts.

Thanks,
~!Donovan
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Andrey,pro on August 17, 2013, 06:29:24 PM
Hello,

it is not a false positive. I found this script (JS:HideMe-B [Trj]) on this site:

Code: [Select]
<div id='hideMe'> <p>Erection failure or Casino en ligne gratuit <a href="http://cafel.fr/">En ligne casino</a>  <p>Erectile dysfunction treatment method has come a Liquid cialis <a href="http://sotrueradio.org/">Cialis with atenolol</a> </div><script type='text/javascript'>if(document.getElementById('hideMe') != null){document.getElementById('hideMe').style.visibility = 'hidden';document.getElementById('hideMe').style.display = 'none';}</script>
I scanned it on virustotal and here results: https://www.virustotal.com/ru/file/a8c41f5b560db3f278ea1cd63fd9f2fc940d62d35f1d9fd2c8cd76cc4d89578b/analysis/1376756619/
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Pondus on August 17, 2013, 06:37:39 PM
also detected by Sucuri.    http://sitecheck.sucuri.net/results/kfum-mus.dk

Malware entry: MW:SPAM:SEO.   http://labs.sucuri.net/db/malware/malware-entry-mwspamseo

HideMeBetter – SPAM injection Variant
http://blog.sucuri.net/2013/07/hidemebetter-spam-injection-variant.html



Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on August 17, 2013, 09:56:36 PM
Get no alerts now on htxp://www.graceniagara.ca/

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: dalt1 on August 18, 2013, 01:03:03 AM
I have a website infected as well. I have looked through many files, but can't find the malicious code. Can someone point me in the right direction on how to find the file that contains the code. I am running a Joomla website.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: REDACTED on August 22, 2013, 04:55:25 AM
Hi
I'm getting this message too, not sure how to access code. Our site is xww.kinikikids.com - are you able to assist?

Rob
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: REDACTED on August 22, 2013, 05:28:48 AM
Hi
I'm getting this message too, not sure how to access code. Our site is xww.kinikikids.com - are you able to assist?

Rob
Thanks, found the code and removed it.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: kd5 on September 11, 2013, 11:29:29 PM
The same message keeps popping up for www.pawstown.org:

&p_prc=C:\Program%20Files\Mozilla%20Firefox\firefox.exe&p_obj=http://www.pawstown.org/&p_var=.%2Ffa%2Fen-us%2Fvirus-alert-champion&p_elm=7&p_lex=317&p_lid=en-us&p_lng=en&p_lqa=0&p_lqe=0&p_lst=0&p_lsu=24&p_pro=0&p_vep=8&p_ves=0&p_vbd=1489&p_hid=dd443ccb-8e24-4f2d-9e3d-5d894a140088]http://www.avast.com/en-us/lp-fr-virus-alert?p_ext=&utm_campaign=Virus_alert&utm_source=prg_fav_80_0&utm_medium=prg_systray&utm_content=.%2Ffa%2Fen-us%2Fvirus-alert-default&p_vir=JS:HideMe-B%20[Trj]&p_prc=C:\Program%20Files\Mozilla%20Firefox\firefox.exe&p_obj=http://www.pawstown.org/&p_var=.%2Ffa%2Fen-us%2Fvirus-alert-champion&p_elm=7&p_lex=317&p_lid=en-us&p_lng=en&p_lqa=0&p_lqe=0&p_lst=0&p_lsu=24&p_pro=0&p_vep=8&p_ves=0&p_vbd=1489&p_hid=dd443ccb-8e24-4f2d-9e3d-5d894a140088 (http://www.avast.com/en-us/lp-fr-virus-alert?p_ext=&utm_campaign=Virus_alert&utm_source=prg_fav_80_0&utm_medium=prg_systray&utm_content=.%2Ffa%2Fen-us%2Fvirus-alert-default&p_vir=JS:HideMe-B%20[Trj)

Quote
Infection Details
URL:   hxtp://www.pawstown.org/
Process:   C:\Program Files\Mozilla Firefox\firefox...
Infection:   JS:HideMe-B [Trj]

Plugged the link into OnlineLink Scan, they claim the site is safe:

http://onlinelinkscan.com/results/pawstown-org/ (http://onlinelinkscan.com/results/pawstown-org/)
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on September 11, 2013, 11:40:46 PM
Well here we find something else: http://sitecheck.sucuri.net/results/www.pawstown.org/

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Pondus on September 11, 2013, 11:46:16 PM
that site contain lots of v i a g r a spam.   ;)

Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: anuoluwa1 on September 16, 2013, 10:49:09 AM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Milos on September 16, 2013, 10:52:18 AM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on September 16, 2013, 11:13:52 AM
In order to do as Milos suggests, use this service to go through the code: http://aw-snap.info/file-viewer/
Fileviewer is an online tool for siteowners and webmasters alike.
When there are remaining questions, report back here on the forum,

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: anuoluwa1 on September 16, 2013, 10:20:35 PM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Milos on September 16, 2013, 10:25:38 PM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Hello,
see http://forum.avast.com/index.php?topic=131579.msg972447#msg972447
Do you have same variant (JS:HideMe-B [Trj] or there is different letter instead of "B")?

Milos
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: anuoluwa1 on September 17, 2013, 06:11:04 AM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Hello,
see http://forum.avast.com/index.php?topic=131579.msg972447#msg972447
Do you have same variant (JS:HideMe-B [Trj] or there is different letter instead of "B")?

Milos
Mine shows an I. I just tried using the link that Polonus said and it still blocked me. I just scanned on virus total and it was a clean scan. Here are the results. https://www.virustotal.com/en/url/3f373af653aed2c145a1736d0044660a90d054fabbc0e7f037fce3b38dc69f24/analysis/1379392651/ Could it be possible that this is a false positive?
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Milos on September 17, 2013, 10:40:59 AM
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Hello,
see http://forum.avast.com/index.php?topic=131579.msg972447#msg972447
Do you have same variant (JS:HideMe-B [Trj] or there is different letter instead of "B")?

Milos
Mine shows an I. I just tried using the link that Polonus said and it still blocked me. I just scanned on virus total and it was a clean scan. Here are the results. https://www.virustotal.com/en/url/3f373af653aed2c145a1736d0044660a90d054fabbc0e7f037fce3b38dc69f24/analysis/1379392651/ Could it be possible that this is a false positive?
Hello,
Avast complains about using certain extensions (such as "sharethis"), which use bad practice (hidden links). Either disable them, or delete the code that hides the links (function dnnViewState() { var a=0,m,v,t,z,x=new Array('9091968376'............)

More info can be found here: http://forum.joomla.org/viewtopic.php?t=795946

Milos
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on September 17, 2013, 10:52:46 AM
For those of you who own websites and would like to know how to remove the trojan, it’s easy – just remove the extra code. Not all files are affected,

polonus

Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: ShadowLady on October 07, 2013, 08:14:18 PM
I know this thread is a little older, but I am getting several warnings from JS:HideMe-J [Trj] with Avast for my personal website, as well.

Here is the link to my website... www.talkintheshadows.com

Can someone please help me?
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mchain on October 07, 2013, 10:28:12 PM
hi ShadowLady,

http://sitecheck.sucuri.net/results/www.talkintheshadows.com/ (http://sitecheck.sucuri.net/results/www.talkintheshadows.com/)
http://urlquery.net/report.php?id=6424328 (http://urlquery.net/report.php?id=6424328)
http://zulu.zscaler.com/submission/show/9043705ff95671493f87cbe11a0d73c8-1381177406 (http://zulu.zscaler.com/submission/show/9043705ff95671493f87cbe11a0d73c8-1381177406)

is a start.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on October 07, 2013, 10:49:18 PM
Additional code hick-up:
talkintheshadows dot com/wp-content/plugins/wp-monalisa/script.js?ver=9999 benign
[nothing detected] (script) talkintheshadows dot com/wp-content/plugins/wp-monalisa/script.js?ver=9999
     status: (referer=talkintheshadows dot com/)saved 5790 bytes d07d89ae1939ebae6820c391d192493eabf1ca05
     info: [img] talkintheshadows dot com/wp-content/plugins/wp-monalisa/
     info: [decodingLevel=0] found JavaScript
     error: undefined variable jQuery
     error: undefined function jQuery
     suspicious:

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on October 07, 2013, 11:20:06 PM
As earlier up in the thread, this site has not been cleansed yet. For this infection the avast! Shield detection is valid and avast detection is unique in this sense.
The scanner of choice to detect these infections is Sucuri's for  htxp://www.dfgwear.com/ -> http://sitecheck.sucuri.net/results/www.dfgwear.com/
(checked a few minutes ago) other scanners alas miss this: http://urlquery.net/queued.php?id=45317449 as they haven't got the right instrumentation to detect this form of SEO Spam insertion. The vulnerable wevsite software to blame (because the version was not being updated in time) is Joomla:
Web application details:
Application: Joomla! - Open Source Content Management - http://www.joomla.org

Web application version:
Joomla Version: 2.5.9
Joomla Version 2.5.x - 3.0.x for: htxp://www.dfgwear.com//media/system/js/caption.js

polonus
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: jefferson sant on October 15, 2013, 03:46:36 AM
I know this thread is a little older, but I am getting several warnings from JS:HideMe-J [Trj] with Avast for my personal website, as well.

Here is the link to my website... www.talkintheshadows.com

Can someone please help me?


url was unblocked
was fixed in VPS update 131014-0.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mpinky on November 27, 2013, 01:44:30 AM
Pls, i'm managing www.kapaniaris-hotel.gr (Joomla version 1.5.25) and it haves the same problem. Trying to access it and the pop up warning is coming up for JS:HideME-J[Trj].
I wasn't able to find any of suspicious "hide" code at my files. I have undestood that it is my homepage that it is infected, since when i put directly in my broswer some other page of the website, there is no problem at all.  Also, i tried through http://aw-snap.info/file-viewer, but the pop up message comes up again before managing to have a report...
Pls, if somebody can help me, i would really appreciate it.
Thanks
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Pondus on November 27, 2013, 01:53:12 AM
Sucuri report. http://sitecheck.sucuri.net/results/www.kapaniaris-hotel.gr

 
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: jefferson sant on November 27, 2013, 02:31:59 AM
Pls, i'm managing www.kapaniaris-hotel.gr (Joomla version 1.5.25) and it haves the same problem. Trying to access it and the pop up warning is coming up for JS:HideME-J[Trj].
I wasn't able to find any of suspicious "hide" code at my files. I have undestood that it is my homepage that it is infected, since when i put directly in my broswer some other page of the website, there is no problem at all.  Also, i tried through http://aw-snap.info/file-viewer, but the pop up message comes up again before managing to have a report...
Pls, if somebody can help me, i would really appreciate it.
Thanks

hello

(http://i.imgur.com/Bx3ujQX.png)


There is a line such as that must be removed
reset or modify the code

(http://i.imgur.com/LVtIrGn.png)

Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mpinky on November 28, 2013, 08:38:54 AM
Pondus and Santiag, thanks for your fast reply. I tried to find the part of the code in my files, but even through cpanel, avast didn't allow me to open or to download the "infected" file so as to edit it. (For a little bit of time, i had also a problem to enter at avast.forum because the pop up warning window appeared again!). So, searching for another solution, i went to the backend and unpublished from my website the AustonSlideshow component....and now everything is OK! No warnings! But in any case....i believe that in general this issue remains a problematic situation that has to be resolved...
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: Pondus on November 28, 2013, 12:34:56 PM
sucuri now say clean.... but still outdated joomla.   http://sitecheck.sucuri.net/scanner/

Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: mchain on November 28, 2013, 11:00:22 PM
sucuri now say clean.... but still outdated joomla.   http://sitecheck.sucuri.net/scanner/
That's gotta be fixed soon, or else you'll soon be back with a similar issue and problem.
Title: Re: Website shows infected with JS:HideMe-B [Trj]
Post by: polonus on November 28, 2013, 11:15:02 PM
Hi mchain,

You are so right with that remark, just read through this when we have outdated Joomla in mind, just an example: http://www.spamfighter.com/News-18099-Hijacked-WordPress-Joomla-Websites-Install-Scareware-SANS-ISC.htm

Also think of the recent grand scale outbreaks of SEO Spam campaigns.

polonus