Author Topic: Web Shield FP? -> Solved  (Read 1942 times)

0 Members and 1 Guest are viewing this topic.

Offline mbrowne

  • Newbie
  • *
  • Posts: 7
Web Shield FP? -> Solved
« on: July 30, 2014, 10:45:41 PM »
Avast Free v8 Web Shield has recently begun alerting on www.sweetmarias.com with:

7/30/2014 1:14:43 PM  http://www.sweetmarias.com/store/|>{gzip} [L] JS:ScriptIP-inf [Trj] (0)

I've run the page through Securi SiteCheck and virustotal and it comes up clean.  Defs version 140729-0

Thanks for any help.
« Last Edit: August 02, 2014, 07:39:38 PM by mbrowne »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Web Shield FP?
« Reply #1 on: July 30, 2014, 10:47:04 PM »
You are using a real old avast version.
Update to the newest one then check again.


Offline Tondah

  • Avast team
  • Jr. Member
  • *
  • Posts: 52
Re: Web Shield FP?
« Reply #3 on: July 31, 2014, 10:03:13 AM »
Hello, there is javascript function called "timedCount()" that does not seems too legit.
This function collects informations from shipping/registration form and send them to internet every 40 miliseconds.

Offline mbrowne

  • Newbie
  • *
  • Posts: 7
Re: Web Shield FP?
« Reply #4 on: July 31, 2014, 06:52:53 PM »
Hello, there is javascript function called "timedCount()" that does not seems too legit.
This function collects informations from shipping/registration form and send them to internet every 40 miliseconds.
Thanks for checking that.  When I made the site owner aware of the alert 2 days ago, he said he was referring it to his "IT guy." 

And I'm still getting the alert after updating to Avast v9.

Offline mbrowne

  • Newbie
  • *
  • Posts: 7
Re: Web Shield FP?
« Reply #5 on: August 02, 2014, 07:38:08 PM »
Thanks for the help Tondah.  The site has been fixed and the owner tight-lipped as to whether is was sloppy code or injection.  Nothing but Avast found it.
« Last Edit: August 02, 2014, 07:39:52 PM by mbrowne »