Massassi Forums Logo

This is the static archive of the Massassi Forums. The forums are closed indefinitely. Thanks for all the memories!

You can also download Super Old Archived Message Boards from when Massassi first started.

"View" counts are as of the day the forums were archived, and will no longer increase.

ForumsDiscussion Forum → Got Koob Face!
Got Koob Face!
2010-01-22, 6:40 PM #1
Ironically enough. :D

A website I designed had apparently been infected with WORM_PKOOBF.SMC. Everytime anyone opens it they get a virus alert for:

JS_ONLOAD.SMF
JAVA_BYTEVER.AT
WORM_PKOOBF.SMC

Most Google searches only told me how to delete it from the actual machine. Any advise on how to delete it from the website? Also, how in the world would it have gotten there in the first place?

I know for a fact that it wasn't there when I've first uploaded the site.
幻術
2010-01-22, 6:52 PM #2
I'm at work right now, so can't test this, but do you think that if I simply re-upload (overwrite) all existing files on the FTP that would do it, or is there more stuff I'd need to do?
幻術
2010-01-22, 7:04 PM #3
Probably. You should only need to do HTTP and JS.

If you know how to do file hashing to compare the files with your local copies that would be a quicker way to identify bad files. You can use "sha1sum *" on linux machines (try md5sum if it's not installed) and on windows there are file hashers out there (I like one that adds a pane to file properties).

2010-01-22, 7:06 PM #4
A brief search led me to a Trend Micro pdf file that explains possible infections in depth, and it looks like it depends on what happened to your website. May be as simple as finding an .exe on the server and wiping it out.
$do || ! $do ; try
try: command not found
Ye Olde Galactic Empire Mission Editor (X-wing, TIE, XvT/BoP, XWA)
2010-01-23, 8:27 AM #5
Replacing the files, particularly any .js or scripts that you've got running should take care of the infection. Furthermore, you may want to update (or request the host to update) any server software you're running like PHP, etc.
-=I'm the wang of this here site, and it's HUGE! So just imagine how big I am.=-
1337Yectiwan
The OSC Empire
10 of 14 -- 27 Lives On

↑ Up to the top!