Author Topic: Agent-AV Trojan in HTLM file  (Read 4920 times)

0 Members and 1 Guest are viewing this topic.

Kurt123

  • Guest
Agent-AV Trojan in HTLM file
« on: July 25, 2008, 02:44:20 AM »
According to AVAST, the index.htm page of my website has been infected with the JS:Agent-AV [trj]. AVAST alerted me of this when I tried to visit my home page in FireFox.

So obviously, when I tried to download the html file (with my FTP program) so I could try to clean it, AVAST flagged it during the download. The only options it gave me were: Move/Rename, Delete, or Move to chest. I also had the option to do "No action," but it wasn't clear what this would accomplish. I chose to move the file to the chest.

There was no option to clean the file. It's probably just some code at the bottom of the html file (like "<script>eval(unescape("EVIL HERE"))</script>).

But now that it's been quarantined, how can I clean the file? I can't even open it manually in notepad where I could simply delete the offending code. I can redownload it, but AVAST will continue to catch it.

I have some trojan cleaners ready to use, but how I can I even access the file since AVAST will always lock it up?

Thanks.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Agent-AV Trojan in HTLM file
« Reply #1 on: July 25, 2008, 09:54:52 AM »
Temporarily disable avast! while you download the file in FTP and edit it.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Kurt123

  • Guest
Re: Agent-AV Trojan in HTLM file
« Reply #2 on: July 25, 2008, 04:14:19 PM »
Temporarily disable avast! while you download the file in FTP and edit it.
Maybe I'm being dense, but doesn't this put me at risk for the Trojan infecting my computer?

Or is this not a concern since I'm downloading it via FTP?

Thanks.

Kurt

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Agent-AV Trojan in HTLM file
« Reply #3 on: July 25, 2008, 04:23:32 PM »
Maybe I'm being dense, but doesn't this put me at risk for the Trojan infecting my computer?
Not if you does not open the html into a browser but into a text editor for edition.

Or is this not a concern since I'm downloading it via FTP?
It does depend on the download way of it when it's already saved in your HDD.
So, don't open the html file into your browser, but just edit it into a text editor, remove the hacked part and upload the html again. Change your passwords.
The best things in life are free.