View Single Post
Old 07-15-2006, 09:02 AM  
Just Jace
Confirmed User
 
Join Date: Jul 2006
Location: Atlanta, Ga.
Posts: 239
here you go - gofuckyourself.com/showthread.php?t=624858&highlight=javascript+troja n

Quote:
Originally Posted by m4yadult
Change your FTP password, remove the script at the bottom of the page that runs the iframe:

[code=trojan stuff on your pages]
<script language="JavaScript">
e = '0x00' + '22';str1 = "%99%C1%CA%
blah blah blah
</script>
[/code]

You might have your host run a check to see what other files were modified at the same time. Pattern to look for is:

Login, Get File, Put File, Get File, Put File, Logout

usually no failed password attempts.

Sources for your password leak: People that have installed software for you in the past, anyone that has had FTP access to your machine, possibly any keylogger on your system.

The script forces the installation of an "start.exe" which connects to a site hosted at "inhoster.com". I donhahaha180;t think ithahaha180;s worth to contact them if you have a look at their site.

The site called us-counter.com and dnv-counter.com belong to a guy from Ukraine and are blacklisted with several records. IPhahaha180;s from the sites and from the hosting company are pretty much the same.
__________________
Do you have a blog that does over 1000 uniques a day?
Contact me to make more money with it
icq:102893553
aol:jacejacejacejace
Just Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote