Author Topic: JS:Redirector-MR [Trj]. Please help me.  (Read 22019 times)

0 Members and 1 Guest are viewing this topic.

pieter_dj

  • Guest
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #15 on: December 10, 2011, 10:20:36 PM »
should I delete the whole of php code or only the javascript code? Just now I only delete the javascript code. I see it has solved the problem. Oh should I delete the php code also? waht do you think spg SCOTT and DavidR ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #16 on: December 10, 2011, 10:22:02 PM »
do not post code in the forum as avast may alarm on it

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #17 on: December 10, 2011, 10:22:13 PM »
Again please post any script examples as images not live code, which could cause an alert.

Thank you very much, spg SCOTT. I have removed the code, but I only remove the javascript code, not the whole of PHP code. so the script now has been like this.

<snip>

Can you check to browse my site again? I think the problem has solved, right? I only need to solve that "Dean Edwards" malware not appear again each time I browse my site.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #18 on: December 10, 2011, 10:28:47 PM »
It seems that the added code in the functions.php was what added the malicious code to the pages as they were created. I can't see the code within the page now.

You also need to ensure that your wordpress version is updated:
From Sucuri...

1. Wordpress internal path: /home/bermain/public_html/gadget-talk.com/wp-content/themes/welding/index.php  Wordpress version outdated: Upgrade required.
...


pieter_dj

  • Guest
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #19 on: December 10, 2011, 10:34:36 PM »
I am sorry, I don't know that the code can make avast alert to this forum. I am apologize. I am cuious, how to see the code in the source code. Because when I see the source code of my site, I can't find that code before I delete that javascript code. I use opera browser. I click menu view and click source, but I can't find the code before I delete the javascript in functions.php. I am curious how you can find the code spg SCOTT ?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #20 on: December 10, 2011, 10:42:57 PM »
Hi folks,

When I do a search query on that malcode on http://sucuri.net/new-malware-evalfunctionpacked.html
and go and try to visit: -http://jsunpack.jeek.org/dec/go?report=961a36cb8a1f4c17e1974106b061279928f04583  immediately avast Web Shield blocks connection to it and alerts for as JS:Agent-HA[Trj]

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #21 on: December 10, 2011, 10:44:55 PM »
I am sorry, I don't know that the code can make avast alert to this forum. I am apologize. I am cuious, how to see the code in the source code. Because when I see the source code of my site, I can't find that code before I delete that javascript code. I use opera browser. I click menu view and click source, but I can't find the code before I delete the javascript in functions.php. I am curious how you can find the code spg SCOTT ?
Scott is using a program called Malzilla

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #22 on: December 10, 2011, 11:05:36 PM »
Avast is right here, see what was reported here: http://blog.armorize.com/2011/10/mass-wordpress-infection-ongoing-most.html  link authors Wayne Huang, Chris Hsiao, NightCola Lin.

Quote from there:
Quote
1. Location of injected script: in the index page of the compromised website.
2. Means of compromise: we believe via a combination of a) stolen WordPress passwords b) backdoors into previously compromised WordPress websites and c) Automated script-injection tools that work in combination of either (a) or (b).
3. Injected script: In the [Details] section we've included an example of an injected script. There are more than 20 variations.
4. Script packer used: Dean Edwards' packer.
5. Malware: Multiple malware will be installed (dropped) onto the visitors machines without the users' knowledge. Antivirus detection rate is around 5 out of 43 vendors on VirusTotal at the time of this writing.
6. Infected websites: A lot of WordPress websites have been hit, a sample list is as follows:


Now the way the infection goes
Quote
he injection has a simple chain:

1. Index page of a WordPress site is injected with script packed by Dean Edwards' packer
2. Javascript generates iframe to a malicious domain registered with changeip.com
3. Browser loads the exploit pack from the malicious domain, hosting on a few fixed IPs including 95.163.66.209 (Russia), 64.131.75.19 (USA), and 182.18.185.82 (India).
 
Link authors: Wayne Huang, Chris Hsiao, NightCola Lin at Armorize malware Blog

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #23 on: December 10, 2011, 11:15:37 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #24 on: December 10, 2011, 11:26:08 PM »
Hi Asyn,

Again this shows how important it is for webmasters to continuously update their website software, here Wordpress, and initially for them to secure their WordPress passwords for instance with the Chap Secure Login plug-in for instance , or one could use an online secret key generator: https://api.wordpress.org/secret-key/1.1/salt/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #25 on: December 10, 2011, 11:42:04 PM »
Again this shows how important it is for webmasters to continuously update their website software, here Wordpress...

+1
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: JS:Redirector-MR [Trj]. Please help me.
« Reply #26 on: December 11, 2011, 01:54:53 AM »
Hi folks, if there is a Dean Edwards packer, there is also an unpacker:
http://dean.edwards.name/unpacker/

Enjoy,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!