Author Topic: wrong alarm:js:Downloader-JU [Trj]  (Read 3243 times)

0 Members and 1 Guest are viewing this topic.

xuebin100

  • Guest
wrong alarm:js:Downloader-JU [Trj]
« on: July 09, 2011, 10:04:10 AM »
When i visit the website:
hxxp://www.nmkjt.gov.cn/  
 I got the alarm as follow:
URL:   file://C:\Documents and Settings\Ma Xuebin\Local Settings\Temporary Internet Files\Content.IE5\I0HWSK7K\show.js
Process:   file://C:\Program Files\Internet Explorer\iexplore.exe
Infection:   js:Downloader-JU [Trj]

i think it's a wrong alarm, and i can not browse the page. Could anybody help me?
« Last Edit: July 09, 2011, 04:01:44 PM by igor »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: wrong alarm:js:Downloader-JU [Trj]
« Reply #2 on: July 09, 2011, 02:32:35 PM »
Hi xuebin100 & Pondus,

Hi xuebin100 make that link in your posting non-click through like -http://etc or hxtp or
http://wXw.etc....
There is definitely something there at the beginning of the page outside HTML,
see the attached image, which represents a malscript for a JS hanging trojan, see malware description found here: http://www.sdpaike.com/201008/508.html (linksource computer networks)
Not many scanners get it: http://wam.dasient.com/wam/diagnose?URL=www.nmkjt.gov.cn (failed to detect); SOSWebscan also failed: Your site URL -http://www.nmkjt.gov.cn has been successfully scanned. And No Malware or badwares found.
Urlvoid and netirk give: Domain does not exist or is unaccessible, because of the redirect and download that starts immediately, so no wrong alarm...but it can be easily found using malzilla,
My malware script detector in Google chrome even flags the search for part of the script code as xss attack...see attached image, example of JS script hung horse...

polonus
« Last Edit: July 09, 2011, 02:53:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!