Joomla Website Malware Issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by 2020autoglass, Jan 8, 2013.

  1. 2020autoglass

    2020autoglass Private E-2

    Recently my Joomla website (www.2020glass.com) was hacked and injected with malicious malware. I had to have all my website files restored from an earlier date to complete solve the problem.

    It turns out either it was not a complete solution, or more malware has been injected into my site. I discovered this by doing a google search for my company and finding that the "Site may be compromised." I contacted HostGator and this is what they responded with:

    >>Per your request we scanned the account for installations of known malicious content. The following is a summary of our findings:

    The following file was found to contain know malicious content:

    File: /home/glass/public_html/templates/rt_zephyr_j15/index.php
    User: glass, Group: glass
    Size: 12139
    Modify: Sun, 06 Jan 2013 17:36:43 -0600 (1357515403)
    Change: Sun, 06 Jan 2013 17:36:43 -0600 (1357515403)

    The file was compromised via Joomla Using the Joomla Admin Login Credentials:

    /home/apachelogs/glass/2020glass.com-Jan-2013.gz: 91.207.6.2 - - [06/Jan/2013:17:36:42 -0600] "POST /administrator/index.php HTTP/1.1" 303 - "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 GTB5"

    This type of compromise is typical of a malware or virus installation on a PC or workstation that has been used to login to the account. The malicious software scans for login credentials or logs keyboard activity and reports it back so as to exploit your account(s). It is necessary that the user do a scan of the infected system and remove any malicious software.<<

    They referred me to your site and I performed all of the instructions for malware removal. The programs found very little if anything wrong. I'm attaching the logs. Any ideas on how/why this is happening? The password I had for my Joomla login credentials was created by HostGator this last time around and was a very difficult password so I don't think anyone could possible have guessed it.

    Thanks,
    Matt
     

    Attached Files:

  2. 2020autoglass

    2020autoglass Private E-2

    One more additional file.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm sorry but you are not having malware problems in the normal sense where there is real malware running on your PC. Some how your website manage to be compromised and the code was modified. The tools we run will not typically find these kinds of problems because they have no easy way to recognize valid code from modified code. You will have to find all the source files that have been modified and manually fix them.

    Many times infections like this occur because people do not install all the necessary security updates for ALL of the software including the software being used to build the website. Or the servers themselves have security holes. Also the server itself may be infected and when you ran our scans, you are running them on your PC not the server that is actually hosting the website.

    If just that one index.php file is infected, you will just have to manually fix it. And then check your backups. If you did a full restore and you still have a problem then either your backup is infected, or it is not a full 100% backup, or the scan that was performed by HostGator could be a false detection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds