Author Topic: Trojan alert in our Website- Urgent  (Read 1867 times)

0 Members and 1 Guest are viewing this topic.

alptankurt

  • Guest
Trojan alert in our Website- Urgent
« on: August 07, 2013, 09:16:44 AM »
Hi.
I'm a software developer in Hurriyet which is the biggest news website in Turkey.
We have a urgert problem, please contact me as soon as possible. Some of visitors that use avast sent us some trojan alert in our website. But our servers are already clean. Please visit the link below and tell me what would we do.
Not just a link, some of our pages have the same problem.
Please tell us whats wrong and how we will fix the urgent problem.

Sample link : http://dosyalar.hurriyet.com.tr/annelergunu/yerler.asp

Note: I guess avast comprehends the script which have a iframe code.(Line 4, <iframe src="http://www.hurriyet.com.tr/uv/dosyalar/uv.asp...)

http://sitecheck.sucuri.net/results/www.hurriyet.com.tr/anasayfa/

Edit: URL:   http://www.hurriyet.com.tr/favicon.ico|{...

processus:   C:\Program Files (x86)\Mozilla Firefox\f...
infection:   JS:Iframe-DBE [Trj]

« Last Edit: August 07, 2013, 10:16:28 AM by alptankurt »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Trojan alert in our Website- Urgent
« Reply #2 on: August 07, 2013, 10:26:11 PM »
Seems indeed the malware there has been closed: http://support.clean-mx.de/clean-mx/viruses?id=12257392
Send a FP report here: http://www.avast.com/contact-form.php

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!