site hacked: iframe src zxstats or bali-planet com script var zaee=

There is a trojan around infecting sites with a encrypted script starting ‘var zaee=”4.5*2,4.5*’ and iframe src linking to zxstats com and bali-planet com

This script is to find right after the body tag of index.html files and infects the PC of a visitor by loading an .exe file.
This file in return seems to scan infected PCs for ftp login user and passwords.
Finding these for example in filezilla’s passwordmanager in C:\Users\username\AppData\Roaming\FileZilla\sitemanager.xml it will send these ftp usernames and passwords out and try to access the sites stored in this file.

These sites will get this script injected via ftp to infect more visitors or even your machine again. (suspicious sites I check with chrome having javascript disabled)

There will be all index, start, home and main files with extension .php or .html infected by an added script.

The problem is the stolen ftp login, not any blog software or CMS running there! Giving ftp passwords out of hand no website software can prevent from changing files!

Sites running on php might not work after infection and show an error instead, like “Parse error: syntax error, unexpected ‘?’ in /xxx/yyy/public_html/index.php on line 18″ (WordPress) or “Parse error: syntax error, unexpected ‘?’ in /xxx/yyy/public_html/modules/boonex/chat/home.php on line 38″ (Boonex Dolphin)

Actually lucky for visitors as in this case the script doesn’t run and will not infect their machines. In .php files the script is added after the last ‘?’ and before the closing ‘>’ and doesn’t work here.

What to do?
First clean your PC from trojans using any anti virus software (malwarebytes, MS Essentials)
Do not store login passwords in Filezilla Servermanager, if you have it there delete it and set it for ‘Ask for Password’ to manually typing it.
Change your infected servers ftp password (and do not store in the ftp program!!)

With your new login go to your site and ‘repair’ all infected files by replacing them with a backup file or editing and removing the malicious code – that’s the biggest task ..

File Extension Xpi Deutsch computerbild site hacked: iframe src zxstats or bali planet com ..de/topic/File Extension Xpi Similar File Extension Xpi Deutsch computerbild on iframe src ://greatshopfilm . cn:8080/.php width184 invisible iframe iframe invisible scary place to hacked hack site how can i get my website on google of the s I work on was hacked and an was placed in all .php files plus in the functions.php file in the wp includes folder. The specfic hack code is: A large number of s have been hacked again in the last few hours with a malware script titledocument.title.replace(/(wW) /)document.write( Tags: mass, infection, iisasp, sites, looking for bnat xxl. zxstats or bali planet com script var zaee There is a trojan around infecting s with a encrypted script starting var zaee 4 Malware campaign against WordPress sites ://recovery hdd.eu/in.cgi6 .. ://almazzao co.eu/in.cgi6 .. browser or Adobe PDF reader you can get compromised by just visiting those hacked s. that all 4 of them have this bit of code injected as the first line: Hostmonster Forums Archive General Questions Help hacked insertion

You might like these posts too!

2 Responses to “site hacked: iframe src zxstats or bali-planet com script var zaee=”

  1. Millie Becraft says:

    Vielleicht solltest du Facebook (z.B. Like Pages) und Twitter auf deiner Page integrieren?! Auf jeden Fall hast du dir viel Mühe dafür gegeben, Danke

  2. internet tablet says:

    It is just a great free FTP client. Filezilla! Can’t live without one

© 2006-2012 www.blogdot.de | Impressum - Kontakt - Datenschutzerklärung