Site keeps getting trojan Help

Discussion in 'Security' started by SKULL, Jul 15, 2007.

  1. #1
    I keep going to my website and seeing somone is getting into the index.php file and adding this in the bottom of the code

    When going to the site it brings up a trojan on my antivirus programme.

    Is there any way to stop this person from adding it back as i keep overrighting the index.php file but he keeps adding it back the next few days.

    Any help would be grand.
     
    SKULL, Jul 15, 2007 IP
  2. Colbyt

    Colbyt Notable Member

    Messages:
    3,224
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    210
    #2
    Since you said over a few days I will assume it is not your temp files that need deleting.

    Change your control panel and ftp passwords. Make them difficult.
    Block the IP number of the site that is being framed.
    Check your logs and see if you can spot the person who is changing your files.
    Block that IP number also if you can find it.
    Mention this to your host in case it is another system user.
     
    Colbyt, Jul 16, 2007 IP
    SKULL likes this.
  3. SKULL

    SKULL Prominent Member

    Messages:
    5,301
    Likes Received:
    303
    Best Answers:
    0
    Trophy Points:
    350
    Digital Goods:
    1
    #3
    Thank you for your reply i have now changed my password again , and have contacted my host.

    Rep added.
     
    SKULL, Jul 16, 2007 IP
  4. zangief

    zangief Well-Known Member

    Messages:
    1,722
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    155
    #4
    By the way can you tell me your hosting company if possible , I have some sites under my control and three of them hosted on the same host (different packages) had trojan the same day.
    The hosting company is a big one and says it was not their fault but if it was my fault my other sites had to be infected, too.
     
    zangief, Jul 16, 2007 IP
  5. Colbyt

    Colbyt Notable Member

    Messages:
    3,224
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    210
    #5
    zangief

    I had a problem last week for the first time ever. If your host's name starts with the letter A, PM me and I will exchange info with you. Since this can happen anywhere anytime I don't want to bash some one in public.
     
    Colbyt, Jul 16, 2007 IP
  6. zangief

    zangief Well-Known Member

    Messages:
    1,722
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    155
    #6
    Yes same here we exchanged pms with Skull , we were on different hosts and my host name begins with m , thanks.
    After this trojan I started to use kaspersky antivirus cause I was warned by someone using that antivirus.Most of the antivirus programs could not catch it.
    Some of these trojans spread on your disk, always have a zipped version of your backups cause they can not get in them.
     
    zangief, Jul 16, 2007 IP
  7. Mxhub

    Mxhub Active Member

    Messages:
    474
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #7
    change your account user/password. They going keep bruteforcing to your account.
    If this is affecting server wide, the server probably got hacked. move away fast.
     
    Mxhub, Jul 17, 2007 IP
  8. clickbuild

    clickbuild Member

    Messages:
    89
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    48
    #8
    Until you figure it out, chmod (change permissions) of files and directories to prevent writing. If you have any open source apps, look to see if there are any security upgrades.
     
    clickbuild, Jul 25, 2007 IP
  9. bloggingseo

    bloggingseo Active Member

    Messages:
    169
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    78
    #9
    That is excellent advice, I think blocking their ip addresses and even go a step further and called their ISP and tell them that they are spamming your website with a trojan.
     
    bloggingseo, Jul 25, 2007 IP
  10. Lastbutnotleast

    Lastbutnotleast Peon

    Messages:
    2,612
    Likes Received:
    105
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I have an hosting account at OXEO.com and I have trojan problems on all my websites

    The index files of all my websites show a Trojan program called Trojan-Downloader.JS.Psyme.hz

    I checked my websites on Google and Google is warning users for this kind of problems for one of my websites

    Does anybody here has experienced the same problem ?

    (no problem with my other sites hosted at DREAMHOST or elsewhere)
     
    Lastbutnotleast, Aug 12, 2007 IP
  11. Colbyt

    Colbyt Notable Member

    Messages:
    3,224
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    210
    #11
    Most likely a link has been loaded in iframe. This link is calling the trogan from another source. If you follow the advice I posted above and then edit your pages to remove the malicious content that usually hides between the <iframe> and </iframe> tags it should solve the problem.

    If they have managed to load it onto your site, the viurs scanner in cPanel might catch it.
     
    Colbyt, Aug 13, 2007 IP
  12. SKULL

    SKULL Prominent Member

    Messages:
    5,301
    Likes Received:
    303
    Best Answers:
    0
    Trophy Points:
    350
    Digital Goods:
    1
    #12
    As Colbyt said its mostly in your index.php or index.htm , html between the <iframe> tags at the very bottom, its not that hard to get rid of but it can be a pain in the arse as there add it back in there more aless every day , best thing you can do is tell your host about it so they can monitor it and when they find the Ip they will take action like they did when i had it.

    After you are 95% that your host has taken care of it , contact google to get your site in review process by clicking here and adding your site in the cleaning house http://www.stopbadware.org/home/clearinghouse it will take about a week , but all my sites are now taken of the blocker.

    Good luck and hope this helps you.
     
    SKULL, Aug 13, 2007 IP
  13. SEOBusiness

    SEOBusiness Well-Known Member

    Messages:
    3,046
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    185
    #13
    Please check your datebases,my site was put some script like this,i deleted the script in my homepage,but it was kept showing up,i checked the datebases,found & deleted the script.Later i changed the name of datebases & the password of my user CP/ftp. You can take a try,just a personal opinion.Good luck.
     
    SEOBusiness, Dec 25, 2007 IP
  14. SKULL

    SKULL Prominent Member

    Messages:
    5,301
    Likes Received:
    303
    Best Answers:
    0
    Trophy Points:
    350
    Digital Goods:
    1
    #14
    Hi thanks for the update its a very old thread now , i fixed the issue a bot ago , somone added it in the index.php file , i just replaced teh index.php file with a new one and changed some permissions and its been fixed for a long time now.
     
    SKULL, Dec 25, 2007 IP