Author Topic: How do I remove JS:Iframe-FG [Trj] ?  (Read 10971 times)

0 Members and 1 Guest are viewing this topic.

drongo

  • Guest
How do I remove JS:Iframe-FG [Trj] ?
« on: June 17, 2012, 08:35:54 PM »
Infection Details
URL:   "hxxp://www.user.dccnet.com/invensol/"
Process:   "C:\Program Files\Mozilla Firefox\firefo...
Infection:   "JS:Iframe-FG [Trj]"

Avast found this in a scan a week ago, and I moved it to the chest.

I run Win XP, IE, FF. Last weekend I also updated my windows security, and did the same today. I did boot scan last night, but it did nothing.

At this point both browsers won't even open my website.
Outside users report that my site says it is infected.
Other websites with the same provider do not.

Thanks ahead,

drongo
« Last Edit: June 17, 2012, 10:32:28 PM by drongo »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
« Last Edit: June 17, 2012, 09:32:21 PM by Pondus »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48625
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #2 on: June 17, 2012, 09:59:58 PM »
Infection Details
URL:  hxxp://www.user.dccnet.com/invensol/
Process:   "C:\Program Files\Mozilla Firefox\firefo...
Infection:   "JS:Iframe-FG [Trj]"

Avast found this in a scan a week ago, and I moved it to the chest.

I run Win XP, IE, FF. Last weekend I also updated my windows security, and did the same today. I did boot scan last night, but it did nothing.

At this point both browsers won't even open my website.
Outside users report that my site says it is infected.
Other websites with the same provider do not.

Thanks ahead,

drongo
Please do not post a possible live infected link. Change the http to hxxp.
Thanks
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #3 on: June 17, 2012, 10:03:50 PM »
Hi drongo,

http://urlquery.net/report.php?id=70099
[setAttribute src] URL=wXw.couchtarts.com/media.php

I see an iframe to a 3rd party php page, which returns a 302 then redirects to either wXw.kigopuer.tk/XXXXXXXX.html (which is 37.157.255.199 mentioned in urlQuery) or a google page. (Replace XXXXXXXX with 8 random digits).

Nice to know avast! detects these kind of appendChilds. :)
https://www.virustotal.com/file/36622ced020ff0e247e5241525a558f1e1cb15d6109a09cf9299385fb1b83aa8/analysis/1339963513/

~~~~~~~~~~`

On how to remove it..

Can you edit your source code directly? If so, search/look for "var _q". The code should look like my attachment. When you find the source, remove all content (including "var _q") inside of the <script> tag. Removing anything else could result in unexpected results.


« Last Edit: June 17, 2012, 10:05:39 PM by !Donovan »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

drongo

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #4 on: June 17, 2012, 10:16:01 PM »
Thank you Bob for esplaining the hxxp protocol.

I asked what the frak this meant about three times on another thread and got moderated for being a newbie.

If it's so important, maybe it should be part of an intro package before people are allowed post.

iroc9555

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #5 on: June 17, 2012, 10:28:51 PM »
Drongo.

Please go to your first post in this thread and edit ( change ) the URL to nonclickable; Edit http:// to hXXp://. It seems to be a malicious address. We don't want anyone clicking that address by mistake.

Thank you.

Infection Details
URL:   "hXXp://www.user.dccnet.com/invensol/"
Process:   "C:\Program Files\Mozilla Firefox\firefo...
Infection:   "JS:Iframe-FG [Trj]"

drongo

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #6 on: June 17, 2012, 10:35:38 PM »
Thanks Iroc for clear direction, and Donovan for tracking things down for me.

My service provider T2 says they couldn't find the virus now, and it might just still be being flagged by my domain service.

Sorry for being such a bother, but this website is my livelihood and I may have already lost clients.

drongo

iroc9555

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #7 on: June 17, 2012, 10:44:51 PM »
No problem.

If you do not have access to the web page codes, you might contact it and direct the web master to Donovan's instructions to get rid of that Iframe.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #8 on: June 17, 2012, 11:23:05 PM »
Hi drongo,

The malware there is now being detected by various av as you can see here: https://www.virustotal.com/file/37730acd892894144ea13059b26d5d18699a5e8e27cc28814f6a8e93c91a6c94/analysis/
For the redirect to -37_157_255_199 as !Donovan mentions, see: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http%3A%2F%2F37.157.255.199%2F&client=googlechrome&hl=nl 
and: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=AS:24961&client=googlechrome&hl=nl

If you contact the webmaster, also give him the link to this thread,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

drongo

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #9 on: June 17, 2012, 11:39:46 PM »
Unfortunately, I am the "webmaster".

I have all the website files on my computer.

Since I cannot seem to locate this virus on my computer anymore (Avast scans), is it safe to assume that it resides in the files held on my provider's server?

If this is so, then would the simplest way to remove it be to overwrite all the files of my site with those from my computer?

If not, then where exactly should I look for this "source code" so I can follow !Donovan's instructions?

Thanks again for your help,

drongo

No problem.

If you do not have access to the web page codes, you might contact it and direct the web master to Donovan's instructions to get rid of that Iframe.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #10 on: June 17, 2012, 11:57:05 PM »
Hi drongo,

I have all the website files on my computer.

Are they in a specific folder?

Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

drongo

  • Guest
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #11 on: June 18, 2012, 12:58:01 AM »
Crisis averted.

I overwrote all my website files on my provider's server and now my site is virus free and apparently no longer blocked.

Thanks to everyone.

Hi drongo,

I have all the website files on my computer.

Are they in a specific folder?

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #12 on: June 18, 2012, 01:02:08 AM »
Glad to see your problem was fixed! :)

Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #13 on: June 18, 2012, 01:07:34 AM »
Hi !Donovan & Drongo,

It is OK now,

polonus
« Last Edit: June 18, 2012, 05:23:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48625
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: How do I remove JS:Iframe-FG [Trj] ?
« Reply #14 on: June 18, 2012, 01:26:52 AM »



That's done it. No more warnings.  :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet