The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Tue Jun 19, 2012 2:59 pm 
Joomla! Intern
Joomla! Intern

Joined: Fri Sep 04, 2009 12:29 pm
Posts: 70
Hi,

My clients site has been infected with a virus Blackhole Exploit Kit (2170).

I do not know how to remove this, could someone offer me some advice.

Many Thanks.


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 3:12 pm 
User avatar
Joomla! Hero
Joomla! Hero

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 2694
Location: Wisconsin USA
The easiest way would be to follow what is posted below. One anti-virus site also recommends this method of repair:

PhilD wrote:

Before you post your security/been hacked topic, it is suggested to do all of the following. Failure to follow the suggestions below may leave your site vulnerable to being hacked again in the future.


You must state what version of Joomla you were using when when the site first became hacked. This can make a difference as to how we approach your individual situation.

[ ] Download and RUN the Forum Post Assistant / FPA Instructions available here and are also included in the download package. Post the generated results in your security/been hacked topic.

[ ] Ensure you have the latest version of Joomla for your 1.5 or 2.5 version of Joomla. Delete all files in your Joomla installation, saving a copy of the configuration.php file.

[ ] Review Vulnerable Extensions List to make sure any 3rd party extensions versions used appear on the vulnerable list.

[ ] Review and action Security Checklist 7 Make sure you've gone through all of the steps.

[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc. Checklist 7 contains a list or recommended scanners.

[ ] Change all passwords and if possible user names for the website host control panel. Change the Joomla database user name and password.

[ ] Use proper permissions on files and directories. They should never be 777, ideal is 644 for files and 755 for directories. The configuration file can be set to 444 which is read only.

[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).

[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.

[ ] Ensure you do not have anonymous ftp enabled.

[ ] Verify individually that any non-Joomla file such as but not limited to that will be placed back on the website such as images, pdf files, files for download, and other documents and files are valid and are supposed to be part of your website.

[ ] Replace the deleted files with fresh copies of a current full version of Joomla (minus the installation directory) you downloaded earlier. Install freshly downloaded copies of any extensions and templates used on the site. If the Joomla database user name and password were changed earlier, then make the necessary changes to the configuration.php file and upload a copy to the website. Upload any non-Joomla files that are necessary for your website. Only by replacing all files in the installation (including extensions and templates) can you be sure to remove the backdoors inserted and hidden in various files and directories More detailed information can be found in the security Checklist 7 link below.

Note: The forum post tool will work with all versions of Joomla.

_________________
PhilD -- Unrequested PM's and/or emails may not get a response.
Security Moderator


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 3:31 pm 
Joomla! Intern
Joomla! Intern

Joined: Fri Sep 04, 2009 12:29 pm
Posts: 70
I will do the above I am just having memory issues running the initial step of diagnostics so am waiting to hear back from my hosting provider. Many Thanks.


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 3:46 pm 
Joomla! Intern
Joomla! Intern

Joined: Fri Sep 04, 2009 12:29 pm
Posts: 70
I have tried running the diagnostics on the website. But am getting fatal memory errors despite having 54mb allocated on my account. My host provider adviced upping it in the php.ini file but I am unable to access this through the back end of joomla as when I click on 'system info' i am getting an error message "Fatal error: Out of memory (allocated 8912896) (tried to allocate 76 bytes)"

Would appreciate any guidance on this. Thanks.


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 6:57 pm 
Joomla! Intern
Joomla! Intern

Joined: Fri Sep 04, 2009 12:29 pm
Posts: 70
Can anyone tell me if this plugin would do the trick.

http://extensions.joomla.org/extensions ... ction/8385


Top
 Profile  
 
PostPosted: Wed Jun 20, 2012 12:11 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11644
Location: The Girly Side of Joomla in Sussex
it depends what "trick" you wanted to pull.
if you cant run the fpa, then move on to step 2 of the checklist and continue

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Wed Jun 20, 2012 8:30 am 
Joomla! Intern
Joomla! Intern

Joined: Fri Sep 04, 2009 12:29 pm
Posts: 70
Want to remove the mailware on my websites. I cant run the step 1 script because my server is throwing me memory errors, despite having enough memory.


Top
 Profile  
 
PostPosted: Wed Jun 20, 2012 2:56 pm 
User avatar
Joomla! Hero
Joomla! Hero

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 2694
Location: Wisconsin USA
mandville wrote:
if you cant run the fpa, then move on to step 2 of the checklist and continue

_________________
PhilD -- Unrequested PM's and/or emails may not get a response.
Security Moderator


Top
 Profile  
 
PostPosted: Tue Jul 03, 2012 3:39 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Tue Jul 17, 2007 12:43 pm
Posts: 147
Location: South West England Near Exeter
I have just had a report that a clients website is infected with Blackhole Exploit Kit (2170) yet when I go there I cannot see anything wrong front end or admin. They are running AVG and I am running McAfee.

I did a search at McAfee but they don't seem to have a record of Blackhole Exploit Kit (2170).

Is this so new McAfee doesnt know about it but AVG does anyone have any information?

Thanks

_________________
http://www.zoomstudio.co.uk
Rules Stifle Creativity


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 



Who is online

Users browsing this forum: No registered users and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group