Author Topic: Does any know anything about JS:Illredir-B[Trj]  (Read 20027 times)

0 Members and 1 Guest are viewing this topic.

widgeteer

  • Guest
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #15 on: January 20, 2010, 10:58:54 PM »
Yesterday I ran across a site that has this trojan -- no problem, though:  I had Avast installed, which warned me and aborted the download. Then I googled the name of the trojan and discovered this forum. 

The site's url: 

http://www.almahatwary.org/

Regards all,

widgeteer

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89652
  • No support PMs thanks
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #16 on: January 20, 2010, 11:10:02 PM »
Looks like the site has been hacked there is an obfuscated script tag at the bottom of the source code (see image, click it to expand). The script is obfuscated to hide its purpose and is suspicious, the line extends way, way, beyond the end of the image example.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34049
  • malware fighter
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #17 on: January 20, 2010, 11:28:26 PM »
Hi widgeteer,

There are two viruses on the site - make the link in your posting non-clickable by putting htxp or WxW:
Virus
Threat found: 2 virtumonde.sci trojan

Name of threat:    53833
Location:    hXtp://www.almahatwary.org/


Name of threat:    53833
Location:    hXtp://www.almahatwary.org/index.htm

pol


« Last Edit: January 20, 2010, 11:30:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

fifa76

  • Guest
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #18 on: May 27, 2010, 05:07:40 AM »
I actually upgrade the script to remove JS:Illredir-B and JS:Illredir-C in same time
If you got some other similar trojan on your website please contact me i try to help and upgrade the script.

HI my website is affected by the same virus also, can you send me the script to remove the virus ? as detected i suspected the virus contented is JS:Illredir-C
can you send the script to my fifa76@gmail.com. thank you

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89652
  • No support PMs thanks
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #19 on: May 27, 2010, 04:24:38 PM »
First we aren't clairvoyant so we need to know what your site URL is, change the http to hxxp to break the link.

Even if we know your site address, we can't send you any script to remove it you have to find the injected script, remove it and close the vulnerability that allowed the script to be injected.

I suggest you remove your email address as a) it can get harvested by spambots trawling the internet and b) we help people through the forums and not email.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34049
  • malware fighter
Re: Does any know anything about JS:Illredir-B[Trj]
« Reply #20 on: May 28, 2010, 09:33:50 PM »
@trzykas

Witamy!      Dziękujemy,

pozdrawiam,

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!