Author Topic: Website shows infected with JS:HideMe-B [Trj]  (Read 64030 times)

0 Members and 1 Guest are viewing this topic.

Offline Andrey,pro

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5012
  • Things happen
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #15 on: August 17, 2013, 06:29:24 PM »
Hello,

it is not a false positive. I found this script (JS:HideMe-B [Trj]) on this site:

Code: [Select]
<div id='hideMe'> <p>Erection failure or Casino en ligne gratuit <a href="http://cafel.fr/">En ligne casino</a>  <p>Erectile dysfunction treatment method has come a Liquid cialis <a href="http://sotrueradio.org/">Cialis with atenolol</a> </div><script type='text/javascript'>if(document.getElementById('hideMe') != null){document.getElementById('hideMe').style.visibility = 'hidden';document.getElementById('hideMe').style.display = 'none';}</script>
I scanned it on virustotal and here results: https://www.virustotal.com/ru/file/a8c41f5b560db3f278ea1cd63fd9f2fc940d62d35f1d9fd2c8cd76cc4d89578b/analysis/1376756619/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #16 on: August 17, 2013, 06:37:39 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #17 on: August 17, 2013, 09:56:36 PM »
Get no alerts now on htxp://www.graceniagara.ca/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

dalt1

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #18 on: August 18, 2013, 01:03:03 AM »
I have a website infected as well. I have looked through many files, but can't find the malicious code. Can someone point me in the right direction on how to find the file that contains the code. I am running a Joomla website.

REDACTED

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #19 on: August 22, 2013, 04:55:25 AM »
Hi
I'm getting this message too, not sure how to access code. Our site is xww.kinikikids.com - are you able to assist?

Rob
« Last Edit: September 17, 2013, 10:53:29 AM by Milos »

REDACTED

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #20 on: August 22, 2013, 05:28:48 AM »
Hi
I'm getting this message too, not sure how to access code. Our site is xww.kinikikids.com - are you able to assist?

Rob
Thanks, found the code and removed it.
« Last Edit: September 17, 2013, 10:53:37 AM by Milos »


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #22 on: September 11, 2013, 11:40:46 PM »
Well here we find something else: http://sitecheck.sucuri.net/results/www.pawstown.org/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #23 on: September 11, 2013, 11:46:16 PM »
that site contain lots of v i a g r a spam.   ;)


anuoluwa1

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #24 on: September 16, 2013, 10:49:09 AM »
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
« Last Edit: September 16, 2013, 10:50:13 AM by Milos »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #25 on: September 16, 2013, 10:52:18 AM »
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #26 on: September 16, 2013, 11:13:52 AM »
In order to do as Milos suggests, use this service to go through the code: http://aw-snap.info/file-viewer/
Fileviewer is an online tool for siteowners and webmasters alike.
When there are remaining questions, report back here on the forum,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

anuoluwa1

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #27 on: September 16, 2013, 10:20:35 PM »
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #28 on: September 16, 2013, 10:25:38 PM »
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Hello,
see http://forum.avast.com/index.php?topic=131579.msg972447#msg972447
Do you have same variant (JS:HideMe-B [Trj] or there is different letter instead of "B")?

Milos

anuoluwa1

  • Guest
Re: Website shows infected with JS:HideMe-B [Trj]
« Reply #29 on: September 17, 2013, 06:11:04 AM »
Hi my site shows the same thing. I just searched and I didn't find any of the reported script. Can you please scan and if you find it let me know where it is? My url is wxw.dfgwear.com
Thanks.
Hello,
search for "hideme" in the html source code.

Milos

I'm running a Joomla site and I didn't find it.
Hello,
see http://forum.avast.com/index.php?topic=131579.msg972447#msg972447
Do you have same variant (JS:HideMe-B [Trj] or there is different letter instead of "B")?

Milos
Mine shows an I. I just tried using the link that Polonus said and it still blocked me. I just scanned on virus total and it was a clean scan. Here are the results. https://www.virustotal.com/en/url/3f373af653aed2c145a1736d0044660a90d054fabbc0e7f037fce3b38dc69f24/analysis/1379392651/ Could it be possible that this is a false positive?
« Last Edit: September 17, 2013, 06:39:08 AM by anuoluwa1 »