Malware Remover for Webmin

Discussion in 'Site & Server Administration' started by Website_Playboy, Aug 31, 2012.

  1. #1
    What is the best and easiest malware remover for webmin? How can i install and use it?
     
    Website_Playboy, Aug 31, 2012 IP
  2. Website_Playboy

    Website_Playboy Member

    Messages:
    115
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #2
    I dont think those are for webmin, installed on a CentOS system.


    Also, what if the malware is in the database? phpmyadmin, mysql etc.?
     
    Last edited: Sep 2, 2012
    Website_Playboy, Sep 2, 2012 IP
  3. RobinInTexas

    RobinInTexas Active Member

    Messages:
    217
    Likes Received:
    14
    Best Answers:
    2
    Trophy Points:
    65
    #3
    Pretty much removal of malware is a manual process.

    The best thing is to make sure any security vulnerabilities are closed. Unfortunately there's no magic wand.
     
    RobinInTexas, Sep 3, 2012 IP
  4. linux7802

    linux7802 Active Member

    Messages:
    110
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    53
    #4
    You can use the "Linux Malware Detect (LMD)" as its working perfectly on the CentOS, the following URL will help you to understand it.

    Linux Malware Detect

    Note : Before making any installation, please make sure that you have understand it else it will cause you problems.
     
    linux7802, Sep 4, 2012 IP
  5. Website_Playboy

    Website_Playboy Member

    Messages:
    115
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #5
    I have used the maldet as suggested and it actually works pretty good. It found and deleted many things but the malware is still active. I think there are some parts located in DB also. What else i can do at this point?
     
    Website_Playboy, Sep 5, 2012 IP
  6. RobinInTexas

    RobinInTexas Active Member

    Messages:
    217
    Likes Received:
    14
    Best Answers:
    2
    Trophy Points:
    65
    #6
    Is the malware still active? Or is the hijack code static on the site?

    If the former, look at the datecodes of the files on the server for something out of the ordinary you might find a clue to the hacked file. If the latter, export the db and examine it.

    You need to find out how they exploited your site so that you can shut the door they used.
     
    RobinInTexas, Sep 6, 2012 IP
  7. Website_Playboy

    Website_Playboy Member

    Messages:
    115
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #7
    Malware comes active randomly. Sometimes one a day sometimes several times a day. But never more than one time at a moment. So when you refresh the page it goes away.

    I have already closed all the doors they came in. I have made the investigation already. I know the type of malware, the codes and bunch of stuff about it. That is how i could remove most of it. But somehow its still somewhere and maldet cant find it. I asume its somewhere in the DB. I can manually examine the db because db is huge.
     
    Website_Playboy, Sep 6, 2012 IP
  8. RobinInTexas

    RobinInTexas Active Member

    Messages:
    217
    Likes Received:
    14
    Best Answers:
    2
    Trophy Points:
    65
    #8
    I have heard good things about these guys, haven't used them http://sucuri.net/

    They have a free scanner that gives a report like this:
    Security report (No threats found):[TABLE]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"] [/TD]
    [TD="bgcolor: transparent"]Blacklisted: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Malware:[/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Malicious javascript: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Malicious iFrames:[/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Drive-By Downloads: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"] [/TD]
    [TD="bgcolor: transparent"]Anomaly detection: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"] [/TD]
    [TD="bgcolor: transparent"]IE-only attacks: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Suspicious redirections: [/TD]
    [TD="bgcolor: transparent"]No[/TD]
    [/TR]
    [TR="bgcolor: transparent"]
    [TD="bgcolor: transparent"][/TD]
    [TD="bgcolor: transparent"]Spam:[/TD]
    [TD="bgcolor: transparent"]No

    [/TD]
    [/TR]
    [/TABLE]

    On a clean site.
    Let us know if the free report tells you anything, and also if you give them a try how it works out.
    I'm not connected with them.
     
    RobinInTexas, Sep 6, 2012 IP
  9. Website_Playboy

    Website_Playboy Member

    Messages:
    115
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #9
    I have checked the website in all (free) security webssites already. They all show secure and clean. Because like i said before, the malware gets activated only sometimes.
     
    Website_Playboy, Sep 6, 2012 IP
  10. yohame

    yohame Well-Known Member

    Messages:
    475
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    138
    #10
    I have a script which could work for most php sites.
     
    yohame, Sep 7, 2012 IP
  11. unzeblog

    unzeblog Peon

    Messages:
    14
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    What is the best and easiest malware remover for joomla
     
    unzeblog, Sep 26, 2012 IP
  12. Website_Playboy

    Website_Playboy Member

    Messages:
    115
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #12
    As long as you have root access and SSH, i would say Maldet is seriously the best. Unfortunately there is no UI and its all commands but i loved it. It worked for my huge malware issue and it ended up finding 80k infected files in my server and cleaned it spotless. So i can tell you the maldet is the best in the market for now.

    and that is???
     
    Website_Playboy, Sep 26, 2012 IP