Author Topic: VBS:Malware-gen  (Read 198488 times)

0 Members and 1 Guest are viewing this topic.

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #195 on: January 03, 2009, 01:24:21 AM »
Does not alarm for me either. Could it be you got installed something bad on your computer? Please, start another thread if you want to get more help.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89377
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #196 on: January 03, 2009, 01:29:40 AM »
I can visit that page without an alert, I can't see anything in the page source that might trigger it, perhaps the webmaster found the script and removed it. Or as kubecj said perhaps something on your system.
 
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

foto

  • Guest
Re: VBS:Malware-gen
« Reply #197 on: January 07, 2009, 10:43:50 AM »
 Same here hxxp://www.live-magazine.eu/
 Can you check it, please. Thanks
« Last Edit: January 07, 2009, 11:26:20 PM by misak »

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #198 on: January 07, 2009, 10:51:22 AM »
Mega-obfuscated script at the end of the page. Not a fp.

NLT

  • Guest
Re: VBS:Malware-gen
« Reply #199 on: January 07, 2009, 09:23:50 PM »
Hello,

I was looking at my "warning" log, and found the following from 6/23/2008:

"VBS Malware-gen has been found in "http://www.yahoo.com/\unp 113810025 file"

I never received any other notification of this problem, other than just noticing it in the log.  I have had no problems, whatsoever, so I am proceeding under the assumption there is nothing to be concerned about.  Am I correct?  Thank you for any replies and corrections.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: VBS:Malware-gen
« Reply #200 on: January 07, 2009, 10:20:26 PM »
Hi foto,

The live-magazine dot eu link is also flagged by finjan as having malicious code,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

theefxman

  • Guest
Re: VBS:Malware-gen
« Reply #201 on: January 10, 2009, 03:00:46 PM »
I am also getting a VBS:malaware-gen message when visiting what I believe to be a safe company website.

hXXp://www.thelawrencegroup.com/

Filename hXXp://www.thelawrencegroup.com/AC_RunActiveContent.js
VBS:Malware-gen
Virus/Worm
090109-0, 01/09/2009

Please let me know if this is a false positive.
« Last Edit: February 21, 2009, 10:54:12 PM by kubecj »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89377
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #202 on: January 10, 2009, 03:29:39 PM »
There is a big chunk of obfuscated document write (javascript) at the bottom of the script.

I have no idea what that is intended to do or why it would be obfuscated in that way or even if it is meant to be there. Since javascript is meant to be a plain language scripting language when obfuscated in this way I get suspicious at what they have to hide.

So it may well be a legit detection but you could submit it (as a possible false positive) for further analysis.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

statikuz

  • Guest
Re: VBS:Malware-gen
« Reply #203 on: February 21, 2009, 09:29:13 PM »
I'm getting this same warning for hXXp://ssbresins.com/. It has the same line of compressed/weird JS as some of these other pages. Just thought I'd chime in.
« Last Edit: February 21, 2009, 09:51:37 PM by kubecj »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89377
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #204 on: February 21, 2009, 09:43:26 PM »
Well if it is your site or one you regularly visit it has probably been hacked.

Considering its location just before the closing Body and HTML taks it certainly looks like code injection into the page.

Please modify your post, changing the http tp hXXP so the link isn't active, avoiding accidental exposure, e.g. hXXp://ssbresins.com/.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: VBS:Malware-gen
« Reply #205 on: March 02, 2009, 08:21:07 PM »
Getting Malware-gen for hXXp://icamaxi.se, any idea if it's a FP?

Thanks
« Last Edit: March 02, 2009, 09:08:28 PM by kubecj »

kubecj

  • Guest
Re: VBS:Malware-gen
« Reply #206 on: March 02, 2009, 08:25:58 PM »
Not a false.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89377
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #207 on: March 02, 2009, 09:05:37 PM »
Getting Malware-gen for hXXp://icamaxi.se, any idea if it's a FP?

As kubecj said not a false positive, a big chunk of javascript (which I have edited to make it easier to see in the image) trying to look like an advert script, but it has an obfuscated link at the end of it. There should be no legitimate reason to do that, e.g. what are they trying to hide.

So it looks like the site has been hacked.

Please modify your post change the http to hXXp to break the link to avoid accidental exposure (as in the quoted text above).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

chaz4j

  • Guest
Re: VBS:Malware-gen
« Reply #208 on: July 14, 2009, 02:42:22 PM »
I plugged in my digital camera and the virus notification came up and said I had VBS:Malware-gen, so I put it in the virus chest and scanned it and it said it was in this file AutoRun.inf. I just had to completely wipe, format and reinstall vista the other day due to not having an antivirus and the first thing I did when I got it running was download avast. I know for sure theres nothing up with my laptop...

If anyone could help me please do!




Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89377
  • No support PMs thanks
Re: VBS:Malware-gen
« Reply #209 on: July 14, 2009, 03:12:42 PM »
This is somewhat different to what is covered here, hacked web sites and is for a different malware name.

- Please start a New Topic of your own as this seems unrelated to the original subject and will just confuse the topic and we will try to help. 
- Go to this link, http://forum.avast.com/index.php, scroll down to the Viruses and Worms forum and click it, click the New Topic button at the top of the list and post there.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security