Author Topic: May it be false positive?  (Read 5836 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
May it be false positive?
« on: October 25, 2014, 04:51:58 PM »
http://www.pljlawsite.com/html/CrpcXXX.htm
Please replace the XXX above with any number between 160 and 170.
All are infected with JS:Includer-ZG [Trj]. May it be false positive?


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37546
  • Not a avast user
« Last Edit: October 26, 2014, 12:16:52 PM by Pondus »

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

REDACTED

  • Guest
Re: May it be false positive?
« Reply #4 on: October 26, 2014, 11:23:17 AM »
I have already disabled 'Block malware URLs', why is the site in question still being blocked?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: May it be false positive?
« Reply #5 on: October 26, 2014, 12:05:28 PM »
Because the site is infected.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: May it be false positive?
« Reply #6 on: October 26, 2014, 12:15:46 PM »
According to the pop-up message, nothing was downloaded from the site. How did avast know that the site was infected?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37546
  • Not a avast user
Re: May it be false positive?
« Reply #7 on: October 26, 2014, 12:22:40 PM »
According to the pop-up message, nothing was downloaded from the site. How did avast know that the site was infected?
Because webshield is scanning the site


and confirmed here
Sucuri report  http://sitecheck.sucuri.net/results/www.pljlawsite.com/html/crpc160.htm

VirusTotal -  html scan
https://www.virustotal.com/nb/file/1cad19bfc19793f3f4c3638bfe072a388574a1b75a3c4d6e65a6bb3e96136594/analysis/



« Last Edit: October 26, 2014, 12:24:35 PM by Pondus »

REDACTED

  • Guest
Re: May it be false positive?
« Reply #8 on: October 27, 2014, 10:18:52 AM »
Because webshield is scanning the site
Do you mean the webpage was scanned when my browser was downloading it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37546
  • Not a avast user
Re: May it be false positive?
« Reply #9 on: October 27, 2014, 10:41:32 AM »
before and blocked.....


REDACTED

  • Guest
Re: May it be false positive?
« Reply #10 on: October 27, 2014, 10:50:40 AM »
Sorry, I don't understand.
Before downloading, the webpage was not yet on my computer, how could avast scan it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37546
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: May it be false positive?
« Reply #12 on: October 27, 2014, 11:56:00 AM »
The site also has other problems: https://asafaweb.com/Scan?Url=www.pljlawsite.com%2Fhtml%2Fcrpc160.htm
error and warnings.
Code hick-up: wXw.pljlawsite.com/js/jquery-ui-1.8.14.custom.min.js benign
[nothing detected] (script) wXw.pljlawsite.com/js/jquery-ui-1.8.14.custom.min.js
     status: (referer=www.pljlawsite.com/)saved 31909 bytes 9d62bdd941e9c624fdc05d31c88ccc842383d9e3
     info: [decodingLevel=0] found JavaScript
     error: undefined variable jQuery
     error: undefined variable c.ui
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var c.ui = 1;  (remote exploit on bash)
          error: line:1: ....^
     suspicious

@Matthew_Wai,

Whenever avast detects malicious code inside the website it immediately blocks it, so it can never land and open up in your browser and contact your computer,  therefore your computer cannot get infested, because it is not allowed to connect to that site.
When avast detects<script src=htxp://fr-cafe.org/vb/chat.php ></script><body lang=EN-US style='tab-interval:.5in'> it alerts, disconnects and you are secure.
To cleanse any remainders of Web Shield contacts and alerts I recommend a full scan of your users file on the computer. This takes a while but should be performed once in a fortnight, at least that is my personal routine.

polonus
« Last Edit: October 27, 2014, 12:02:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: May it be false positive?
« Reply #13 on: October 29, 2014, 03:16:54 PM »
so it can never land and open up in your browser and contact your computer,
Do you mean it cannot land my harddisk?