Author Topic: JS:HideMe-J [Trj] false positive  (Read 6335 times)

0 Members and 1 Guest are viewing this topic.

galactex

  • Guest
JS:HideMe-J [Trj] false positive
« on: November 23, 2013, 09:05:27 PM »
My website has not been updated in over a year, but just recently Avast! started detecting a JS:HideMe-J [Trj] false positive whenever someone visits.  No other virus protection sees anything.  I have tried reporting this, but get no response.  The website is wxw.galactex.com
« Last Edit: December 13, 2013, 09:46:33 AM by Milos »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: JS:HideMe-J [Trj] false positive
« Reply #1 on: November 23, 2013, 09:09:57 PM »
why does everyone say false positive when avast detect infected websites   ::)

Your site is injected With HideMe spam   http://sitecheck.sucuri.net/results/www.galactex.com
and the spam is about cash loan..

SPAM:seo  http://labs.sucuri.net/db/malware/malware-entry-mwspamseo

hideme spam  http://blog.sucuri.net/?s=hideme+



« Last Edit: November 23, 2013, 09:14:03 PM by Pondus »

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: JS:HideMe-J [Trj] false positive
« Reply #2 on: November 23, 2013, 09:10:37 PM »
Even your link is blocked Pondus. :D
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: JS:HideMe-J [Trj] false positive
« Reply #3 on: November 23, 2013, 09:12:05 PM »
« Last Edit: November 23, 2013, 09:30:06 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:HideMe-J [Trj] false positive
« Reply #4 on: November 23, 2013, 10:35:18 PM »
Yes, and it is not only avast! that detects this SEO Spam. A spam check via Web Security Test revealed:
Quote
Suspicion of Spam

y way to see the finance best payday loans <a href="hxtp://paydayloans10doqd.com/payday-loans/best-payday-loans" title="...
see the image of the script attached.
External links -> http://urlquery.net/queued.php?id=52204875 etc.

See web code: http://www.rexswain.com/cgi-bin/httpview.cgi?url=http://www.galactex.com/&uag=MSIE+8.0+Trident&ref=http://www.google.com&aen=&req=GET&ver=1.1&fmt=AUTO

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline midnight

  • Massive Poster
  • ****
  • Posts: 2473
Re: JS:HideMe-J [Trj] false positive
« Reply #5 on: November 23, 2013, 10:54:08 PM »
@Pondus.....This popped up when I clicked on your first link.
.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:HideMe-J [Trj] false positive
« Reply #6 on: November 23, 2013, 11:16:34 PM »
Hi -midnight,

That was avast!'s Web Shield in action because there was so much of the SEO Spam malcode revealed on the Sucuri scan site scan
that the avast! Web Shield didn't know any better than to alert this as if it were the real McCoy...
Later on you got an explanation as to what happened inside the browser.
So there was absolutely no danger from clicking Pondus's link. This was not real SEO-Spam malware,
but something innocent that looked like the real malcode.
Bet you are glad the avast! Web Shield is that trigger happy, it even shoots when it thinks it smells danger. ;D.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

hostricity

  • Guest
Re: JS:HideMe-J [Trj] false positive
« Reply #7 on: December 12, 2013, 08:29:49 PM »
why does everyone say false positive when avast detect infected websites   ::)


Perhaps, because Avast is registering false positives.

I used your suggested Sucuri on a WordPress website that is triggering HideMe-J. Sucuru found the site to be clean.

My friend updated her WordPress website to the latest 3.7.1 this morning and updated the plugins. Now, she is getting this alert from  Avast and the site is blocked.

She tried putting the url in the bypass on Avast and it blocked it again.

What's worse, is that Avast provides no information useful in identifying the source of the problem.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: JS:HideMe-J [Trj] false positive
« Reply #8 on: December 12, 2013, 08:37:47 PM »
Quote
Perhaps, because Avast is registering false positives.
always?
i dont have any statistic, but from all the infected website posts that comes in here and websites we check i would say avast is correct in more the 90% of the cases

Quote
My friend updated her WordPress website to the latest 3.7.1 this morning and updated the plugins. Now, she is getting this alert from  Avast and the site is blocked.
what is the message from avast? .... a screenshot maybe
and what is the URL you have problem with?


« Last Edit: December 12, 2013, 08:45:29 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:HideMe-J [Trj] false positive
« Reply #9 on: December 13, 2013, 12:33:19 AM »
Avast is one of the rare av solutions that is so accurate with the Web Shield detection.
It will get all those SEO-SPAM detections, like JS-Hide etc. very accurately.
When it was injected deliberately as Blackhat SEO-SPAM who is going to admit to these detections on their websites  ??? ?
For all other cases feel glad avast! has this accurate detection.
Love these avast! shields they cover so much, they detect, block and in such a way protect.
Where users haven't installed  NoScript and RequestPolicy extensions in the browser to thwart all of first line and  third party script infections,
the avast shields is the next best thing that was to come to your browser defense,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: JS:HideMe-J [Trj] false positive
« Reply #10 on: December 13, 2013, 09:48:50 AM »
My website has not been updated in over a year, but just recently Avast! started detecting a JS:HideMe-J [Trj] false positive whenever someone visits.  No other virus protection sees anything.  I have tried reporting this, but get no response.  The website is wxw.galactex.com
Hello,
if you see detection JS:HideMe-J [Trj]then there is crypted JavaScript. Search for "parseInt" in html source code.

Milos