efm-vogue - Fixed Web Site Trogan/Virus Infection

VST, AU, AAX, CLAP, etc. Plugin Virtual Instruments Discussion
RELATED
PRODUCTS

Post

AVG is now reporting my website free of all Trogan/Virus'. Somehow, someone installed the Framer Z script. It has been removed.

It was only the web site that was infected. The downloads were and are safe.

I could not find any info on Framer Z outside of AVG picking it up. If you know something speak up.

------------------------------------------------------------------------


My latest SE project.

_classic emulation +
_low cpu
_working wheels
_extended classic + phrase Arp

Enjoy

http://www.ele4music.com/vst/efm-vogue.zip
Image

[mod edit: I don't know whether you've removed all the malware, but just in case I've edited the URL and IMG contents above. Feel free to change them back (and to delete this message) when you're sure nothing wicked that way comes.]

Thank you! Even though these particular links were always clean it's good to be safe. I've been to every page on my site and AVG reports it clean so I've restored the links. If anyone gets another warning I'll disable them again.
Last edited by tomg on Thu Apr 03, 2008 10:21 pm, edited 3 times in total.

Post

Sweet Tom, thanks! Will post some more later :)
..what goes around comes around..

Post

Thanks for the freebie...will try it later.

I clicked on your "www" link and received a virus alert from F-Secure saying

Code: Select all

Malicious code found in file C:\DOCUMENTS AND SETTINGS\SZ175P\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\D59VCFKP\ELE4MUSIC[1].HTM.
Infection: Trojan-Downloader.HTML.Agent.ij
Action: The file was deleted.
Virus Detected.  Please contact your local Service Desk.
I cleared my cache and tried it again with the same result.

Behind the message box, a page loaded with the address:

http://www.ele4music.com/efm/

The page title was "WordPress" and contained a notice saying something about an error establishing a database connection.

After clearing the message box, I reloaded the page (Shift-F5). The same page reloaded with no virus message.

Anyone else get this? :shrug:

SWTrex
"Sometimes I think of Abraham...
How one star he saw had been lit for me"

Post

I download everything from you. Thanks Tom.
You can't always get what you waaaant...

Post

SWTrex wrote:..

Anyone else get this? :shrug:

SWTrex
No, a 'Error establishing a database connection' error.
-- Regards MrM --

Post

SWTrex wrote:Thanks for the freebie...will try it later.

I clicked on your "www" link and received a virus alert from F-Secure saying

Code: Select all

Malicious code found in file C:\DOCUMENTS AND SETTINGS\SZ175P\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\D59VCFKP\ELE4MUSIC[1].HTM.
Infection: Trojan-Downloader.HTML.Agent.ij
Action: The file was deleted.
Virus Detected.  Please contact your local Service Desk.
I cleared my cache and tried it again with the same result.

Behind the message box, a page loaded with the address:

http://www.ele4music.com/efm/

The page title was "WordPress" and contained a notice saying something about an error establishing a database connection.

After clearing the message box, I reloaded the page (Shift-F5). The same page reloaded with no virus message.

Anyone else get this? :shrug:

SWTrex
I got that.

Post

mhemnarch wrote:
SWTrex wrote:Thanks for the freebie...will try it later.

I clicked on your "www" link and received a virus alert from F-Secure saying

Code: Select all

Malicious code found in file C:\DOCUMENTS AND SETTINGS\SZ175P\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\D59VCFKP\ELE4MUSIC[1].HTM.
Infection: Trojan-Downloader.HTML.Agent.ij
Action: The file was deleted.
Virus Detected.  Please contact your local Service Desk.
I cleared my cache and tried it again with the same result.

Behind the message box, a page loaded with the address:

http://www.ele4music.com/efm/

The page title was "WordPress" and contained a notice saying something about an error establishing a database connection.

After clearing the message box, I reloaded the page (Shift-F5). The same page reloaded with no virus message.

Anyone else get this? :shrug:

SWTrex
I got that.
I think your virus checkers went nuts because my wordpress database went down for a short time. It's working now. Try again please.

Post

I'm at work tom and I got a virus detection (via Norton) when I visited your page and checked out Stompshop...
Whassup wit dat?

Post

pattonfreak1 wrote:I'm at work tom and I got a virus detection (via Norton) when I visited your page and checked out Stompshop...
Whassup wit dat?

That sucks! I think I found it though... Please try again and let me know if I got it.

Someone changed this...

Code: Select all

<META HTTP-EQUIV="Refresh"
      CONTENT="1; URL=http://www.ele4music.com/efm/">
To this...

Code: Select all

<META HTTP-EQUIV="Refresh"
      CONTENT="1; URL=http://www.ele4music.com/efm/">
<script>eval(unescape("[mod edit: deleted script segment to be on the safe side]")); </script>

Post

Just tried it again. This time, your page loads ("EFM electronics for music") but I still get a message from F-Secure:

Code: Select all

Malicious code found in file C:\DOCUMENTS AND SETTINGS\SZ175P\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\4C2ZF59D\EFM[1].HTM.
Infection: Trojan-Downloader.HTML.Agent.ij
Action: The file was renamed.
Virus Detected.  Please contact your local Service Desk.
SWTrex
"Sometimes I think of Abraham...
How one star he saw had been lit for me"

Post

Yea, Zone Alarm keeps catching a Trojan anytime I visit the page. :shrug:
"Music is a hidden arithmetic exercise of the soul, which doesn't know that it is counting." - Gottfried Wilhelm von Leibniz
---
e to the i pi plus one equals zero

Post

alright, i'll be waiting on this one... :p

Post

SWTrex wrote:Just tried it again. This time, your page loads ("EFM electronics for music") but I still get a message from F-Secure:

Code: Select all

Malicious code found in file C:\DOCUMENTS AND SETTINGS\SZ175P\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\4C2ZF59D\EFM[1].HTM.
Infection: Trojan-Downloader.HTML.Agent.ij
Action: The file was renamed.
Virus Detected.  Please contact your local Service Desk.
SWTrex
Got it! Thanks it was buried in index.php.

Post

datapark wrote:alright, i'll be waiting on this one... :p
It's safe to come over now.. :)

Post

Move to Movable Type and truly be safe. Wordpress installs that aren't updated within a day of the latest security update are oft-hacked.

Post Reply

Return to “Instruments”