Jump to content

geocaching.com website has been infected


kewfriend

Recommended Posts

I use the CA Pest Patrol and Antivirus which reported this JavaScript driveby infection from the geocaching.com website about 15 mins ago now. False positives are (of course) reported but until the all clear is given I woyld refrain from using the site without adequate protection.

Link to comment

It is a false positive. Most likely in the heuristics detection portion of your virus detection software. Go on in your virus detection program and either turn heuristics detection down to a lower level or turn it off all together. Don't worry this will NOT open your system up to viruses as this has no effect on signature detection.

 

The classic type of virus detection is signature detection. Signature detection is when little bits of code that are unique to that particular virus (the signatures) is compared to files on your system for a match. In signature detection it is very rare for a non-virus program to have the same signature as a virus. Heuristics detection is new way of detecting potential virus activity. It looks for certain virus like behavior. In heuristics detection because it looks for behavior cues it is more likely that it could mistake normal program behavior for virus activity particularly if the detection level is set to strict or high.

 

If you want more information you can read How Virus Detection Works.

Link to comment

The classic type of virus detection is signature detection. Signature detection is when little bits of code that are unique to that particular virus (the signatures) is compared to files on your system for a match. In signature detection it is very rare for a non-virus program to have the same signature as a virus. Heuristics detection is new way of detecting potential virus activity. It looks for certain virus like behavior. In heuristics detection because it looks for behavior cues it is more likely that it could mistake normal program behavior for virus activity particularly if the detection level is set to strict or high.

 

Funny that one of the exe's in our software package (Real Estate market) was showing, after we compiled one of the daily builds, as one of the Banker virus variants. We ended up rearranging some atributes in the code and it fixed the false positive. It was quite the scare around the office until it was figured out to be a false positive...

Link to comment
Guest
This topic is now closed to further replies.
×
×
  • Create New...