ccfelomvhk virus on WordPress based sites

Invisible

JF Admin
Joined
Feb 26, 2006
Posts
16,286
Reaction score
8,380
Hello buddies, there's this virus ccfelomvhk.com that's attacking so many sites. Your site will be attempting to download a virus, you need to get your space swept!

This issue actually involves several sites, running versions 2.1.3, 2.3, 2.3.1, 2.3.2, 2.3.3 and 2.5

Try to do this:

1. Keep searching for wp-info.txt to make sure it's not around, if so, delete it.

find . -name wp-info* 2. get rid of all _new _old .jpgg .giff and .pngg
find . -name *_old* -exec rm '{}' \;

3. find all instances of the backdoor account looks like

<?php if(md5($_COOKIE['_wp_debugger'])=="randomhash"){ Use grep to find this:
grep -ri _wp_debugger * *.php Then do a global search and replace (for now) to replace _wp_debugger with 'unknown'
find . -name '*.php' | xargs perl -pi -e 's/_wp_debugger/unknown/'

4. Upgrade all installations to 2.5

5. Use phpmyadmin to remove the hidden 'wordpress' user account from the wp_users table in the database

6. Reset all user passwords by replacing the MD5 hash through the database directly.


All doesn't work?

Probably follow this:
 
If you have got a WordPress based user content management system, i think it's best not to allow anonymous posting of comments from your website visitors, I know there is no silver bullet solution to this, but at least in that way you can to SOME POINT limit spammers and some attacks similar to above.

SteveD.
 
A Trojan program will try to reach your pc once you visit an infected site:

Trojan name: Trojan-Clicker.HTML.IFrame.od

Target: wp-includes/js/thickbox/loadingAnimation.gif
 
A Trojan program will try to reach your pc once you visit an infected site:

Trojan name: Trojan-Clicker.HTML.IFrame.od

Target: wp-includes/js/thickbox/loadingAnimation.gif

......it is about time people revisited this thread: Viruses, malware, spyware, trojans Updates

..... and specifically on that thread, i highlighted on the following post the emergence of 'iFrame' attacks: http://www.jamboforums.com/showpost.php?p=168126&postcount=69


....be wary people!!! 🙁

SteveD.
 
Cookies are required to use this site. You must accept them to continue using the site. Learn more…