Author Topic: HTML:HideMe-F [Trj]  (Read 9671 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
HTML:HideMe-F [Trj]
« on: December 02, 2014, 06:19:53 AM »
Everytime that I pull up a website I get a virus warning message.   Normally I wouldn't care and would just simply avoid the website, but this is a website that I manage and know (well assume) that it is virus free.  I use ipage with wordpress.  I did run it against virustotal.com and sucuri.net but got no hits for viruses.

Object:  hxtp://www.carolschaufel.com
Infection:  HTML: HideMe-F [Trj]
Process:  BROWSER EXECUTABLE

Any suggestions, help, or direction to go would be awesome.

Thanks
« Last Edit: December 02, 2014, 10:23:32 PM by Milos »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
« Last Edit: December 02, 2014, 07:54:11 AM by Pondus »

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #2 on: December 02, 2014, 07:53:47 AM »
I also got the same virus warning today on my Wordpress website! Is there an outbreak out there. Any comment and suggestion from Avast please?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: HTML:HideMe-F [Trj]
« Reply #3 on: December 02, 2014, 07:54:42 AM »
I also got the same virus warning today on my Wordpress website! Is there an outbreak out there. Any comment and suggestion from Avast please?
and your URL would be?


REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #4 on: December 02, 2014, 08:20:54 AM »
duo2tek.com Tks

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #5 on: December 02, 2014, 08:41:23 AM »
I actually rarely log into the site and the passwords used are quite lengthy so it's probably on the wordpress side for me.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: HTML:HideMe-F [Trj]
« Reply #6 on: December 02, 2014, 12:01:55 PM »
Hi guys,
check for this code on your respective sites:

carolschaufel.com: <style>.mnz0{position:absolute;clip:rect(468px,auto,auto,481px);}</style>
duo2tek.com: <style>.cxo3{position:absolute;clip:rect(487px,auto,auto,419px);}</style>

What this does is it hides div with class mzn0 (or cxo3), which includes spammy links. Deleting the code above should make the spammy links appear on your website, and also make Avast stop flagging your websites.
Honza

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #7 on: December 02, 2014, 02:57:49 PM »
Tks Honzaz for responding. Did what u suggested. The avast alerts continue to exist. I didn't do anything to this site for some time, but today the avast alerts up pop up from no where. I tried virustotal too but nothing detected. It seems only avast is detecting this, hope avast can through some light on this alert. Tks in advance!

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2295
Re: HTML:HideMe-F [Trj]
« Reply #8 on: December 02, 2014, 03:31:35 PM »
Tks Honzaz for responding. Did what u suggested. The avast alerts continue to exist. I didn't do anything to this site for some time, but today the avast alerts up pop up from no where. I tried virustotal too but nothing detected. It seems only avast is detecting this, hope avast can through some light on this alert. Tks in advance!

Hello,
if the detection has same name, then the code is still there.

Milos

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #9 on: December 02, 2014, 09:21:56 PM »
I looked all over for that code and couldn't find even things close to it.  Any other suggestions.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: HTML:HideMe-F [Trj]
« Reply #10 on: December 02, 2014, 10:20:16 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #11 on: December 02, 2014, 10:45:59 PM »
Well isn't that cool.  That must be a translation via the server.  I downloaded all of the code and searched through indexing through all of the code and didn't find that.  I'll log into a VM with Guest account into the Wordpress directly and see if I can reload the wordpress or do an upgrade to see if that takes care of it.  I'm gonna do upgrades on any of the modules that are installed.  I'm pretty sure that'll take care of it.  Either way I'll post my findings/results on here.

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #12 on: December 03, 2014, 09:35:21 AM »
The odd and scary thing is that the www address in that image points to a governmental affairs & ethics consulting firm.

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #13 on: December 03, 2014, 10:08:29 AM »
The infection seems to be gone.  I looked everywhere for every key phrase that I could come up with in that image.  I even paged through all the wordpress tables and came up empty.  But I didn't think that I did anything that would bump the infection.  I'm glad that it's gone, but curious as to why.  I'm going to change passwords and follow that protocol.

REDACTED

  • Guest
Re: HTML:HideMe-F [Trj]
« Reply #14 on: December 03, 2014, 10:13:36 AM »
nevermind...  like a crazy X...  never goes away... lol