<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bleuken.com &#187; Search Results  &#187;  trojans</title>
	<atom:link href="http://www.bleuken.com/search/trojans/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>http://www.bleuken.com</link>
	<description>SEO, Programming, Gadgets, Boxing, Etc.</description>
	<lastBuildDate>Sun, 15 Jan 2012 12:16:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Removal and Prevention of Gumblar.cn Infections</title>
		<link>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/</link>
		<comments>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/#comments</comments>
		<pubDate>Wed, 06 May 2009 02:27:03 +0000</pubDate>
		<dc:creator>bleuken</dc:creator>
				<category><![CDATA[Some Tips]]></category>
		<category><![CDATA[Gumblar.cn]]></category>
		<category><![CDATA[PHP Exploits]]></category>
		<category><![CDATA[PHP Hacks]]></category>

		<guid isPermaLink="false">http://www.bleuken.com/?p=854</guid>
		<description><![CDATA[Gumblar.cn is a website is listed to be suspicious and contains several exploit scripts and trojans that might harm and infect computers. Google marked it as not safe for browsing. I first encountered on a website that I am working on and seen how and where it infects the website. What the trojan did on [...]<p><a href="http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/">Removal and Prevention of Gumblar.cn Infections</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>



No related posts.]]></description>
			<content:encoded><![CDATA[<p>Gumblar.cn is a website is listed to be suspicious and contains several exploit scripts and <a href="http://www.bleuken.com/search/trojans">trojans</a> that might harm and infect computers. Google marked it as not safe for browsing. I first encountered on a website that I am working on and seen how and where it infects the website. What the trojan did on the site is it embeds its encrypted scripts on .HTML, .JS and .PHP files. You can find the Javascript of the trojan on .HTML files prior to the &lt;body&gt; tag while it embeds itself on .JS files at the bottom most of the said script file. On .PHP files, it usually infects INDEX.PHP files and embeds itself either at the top or bottom of the file. I also found some infections on common .PHP files that are usually INCLUDEd as a constant file of the site. The current anti-virus that detects the said virus was AVAST Home Edition with Web Shield and Networking Shield ON.</p>
<p>Here&#8217;s what you will see if you will try to surf a site on Google Chrome that is infected by the trojan coming from the said site:</p>
<p><img class="aligncenter size-full wp-image-855" title="gumblar-cn-googlechrome" src="http://www.bleuken.com/wp-content/uploads/2009/05/gumblar-cn-googlechrome.jpg" alt="gumblar-cn-googlechrome" width="479" height="183" /></p>
<p><span id="more-854"></span>Now, how to remove it from your website? Well I found no reference on the net to remove it instantly so what I did is I removed the trojan scripts on each file (.JS, .HTML, INDEX.PHP) that I suspected for infection using Filezilla (FTP client program). For the WordPress infection, what I only did was I re-updated / upgraded the site to the latest version which causes the process to override existing files then remove the script from the WP-CONFIG.PHP file. This is the only file that is not overwritten by the said process that&#8217;s why I need to remove the trojan scripts manually.</p>
<p>As always, prevention is better than cure to avoid the pain of fixing the problems it cause to the site and to the owner. Here are some of my suggestions and recommendations I found from different web hosting sites regarding avoidance of <a href="http://www.bleuken.com/search/hacking">hacking</a> and malware infections on your site:</p>
<ol>
<li>Change the file attributes of the files that doesn&#8217;t require writing permissions. I usually set my files to 755 attributes (MOD 755)</li>
<li>Update your antivirus virus database and enable or use network + web shield features at all times. Usually infection of websites starts from the local PC that uses to upload new files.</li>
<li>Read this PHP Security fixes recommended by a web hosting company. It contains comprehensive tips on how to avoid PHP exploits and hacks. Read it carefully and apply it if it is possible.</li>
</ol>
<p>If you have any better solutions out there or any recommendations on dealing on this kind of exploits/hacks, feel free to leave it here. I am sure that a lot of people will really highly appreciated the help that you can provide.</p>
<p><a href="http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/">Removal and Prevention of Gumblar.cn Infections</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Free Tools for Virus, Worm, Malware &amp; Spyware Prevention &amp; Removal</title>
		<link>http://www.bleuken.com/free-tools-virus-worm-malware-20081120/</link>
		<comments>http://www.bleuken.com/free-tools-virus-worm-malware-20081120/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 15:18:48 +0000</pubDate>
		<dc:creator>bleuken</dc:creator>
				<category><![CDATA[Some Tips]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Anti-Spyware]]></category>
		<category><![CDATA[Anti-Virus]]></category>

		<guid isPermaLink="false">http://www.bleuken.com/?p=630</guid>
		<description><![CDATA[Whenever you are online, it seems that you just can&#8217;t avoid different forms of malicious codes to invade your system. It seems that these annoying bugs are everywhere. Of course dealing with them is not really easy and it will really cost you both money and time to avoid and remove it. Now, I have [...]<p><a href="http://www.bleuken.com/free-tools-virus-worm-malware-20081120/">Free Tools for Virus, Worm, Malware &#038; Spyware Prevention &#038; Removal</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>



Related posts:<ol><li><a href='http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/' rel='bookmark' title='Removal and Prevention of Gumblar.cn Infections'>Removal and Prevention of Gumblar.cn Infections</a></li>
<li><a href='http://www.bleuken.com/conficker-worm-virus-removal-and-prevention-20090121/' rel='bookmark' title='Conficker Worm/Virus, Removal and Prevention'>Conficker Worm/Virus, Removal and Prevention</a></li>
<li><a href='http://www.bleuken.com/malware-that-hijacks-google-adsense-20080715/' rel='bookmark' title='Malware that Hijacks Google &amp; Adsense'>Malware that Hijacks Google &#038; Adsense</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-634" title="Bug" src="http://www.bleuken.com/wp-content/uploads/2008/11/a-bug.png" alt="" width="106" height="92" />Whenever you are online, it seems that you just can&#8217;t avoid different forms of malicious codes to invade your system. It seems that these annoying <em>bugs </em>are everywhere. Of course dealing with them is not really easy and it will really cost you both money and time to avoid and remove it. Now, I have listed here some <strong>free tools</strong> that you can use to prevent and remove common virus, worms, spywares or malwares. These are some of the tools that I personally used to avoid and fix these kind of &#8220;infections.&#8221;</p>
<p><span id="more-630"></span>1. <strong>Malwarebytes&#8217; Anti-Malware</strong>. This a free downloadable freeware tool that allows you to scan and clean your PC from different kind of malware infections. It is freely available online at <a href="http://www.malwarebytes.org" rel="nofollow" target="_blank">Malwarebytes.org</a> and compatible with Windows 2000, XP and Vista. Its simple interface and light use of computer resources make it to scan the computer very fast.</p>
<p>2. <strong>NOOB.Killer.Leerz</strong>. I think this free virus and world removal tool was made by a Filipino basing on its homepage which is located at<del> <a href="http://leerz25.sitesled.com/" rel="nofollow" target="_blank">http://leerz25.sitesled.com/</a></del>(the site is not existing anymore but I found an archive of the tool and you can <a href="http://www.fileserve.com/file/8zVRtBQ " rel="external nofollow" target="_blank">download NOOB.Killer.Leers here</a>.) It targets virus and worms such as IMGKulot.VBS (this is a VBScript worm that uses autorun.inf to spread itself), Funny UST Scandal virus or also known as YahLover virus, Krag, KAVO and many other. Actually this was recommended to me by a friend technician who use this to fix problems of his clients. I&#8217;ve tried this one to remove the KAVO and Funny UST Scandal virus on our school&#8217;s PC and I found it very effective.</p>
<p>3. <strong>TrendMicro HijackThis</strong>. This free tool is for those who knows how to read the registry. It is use to list all the running process currently executing on the background of the PC and all the programs that ran during start-up. Actually this is the tool that I recommend to my readers who asked for advice about their problems on their PC. This program produces a .LOG file that shows all the said information and I asked them to send it to me via email so I could analyze the .LOG file.</p>
<p>4. <strong>SmitFraudFix</strong>. A freeware tool from S!Ri which is created to remove rogue anti-spyware applications that uses Trojans to issue fake taskbar, security alerts or that change your background in order to scare you into purchasing the full commercial version of their software. I used this program to remove the infection of SpySheriff / Winstall.exe and Antivirus 2009 infection. You can download and read information about this tool from <a href="http://www.bleepingcomputer.com" rel="nofollow" target="_blank">BleepingComputer.com</a>.</p>
<p>5. <strong>AVAST, AVG, Avira. </strong>These are the three free anti-virus that I&#8217;ve been using for several years. What I like with AVAST (<a href="http://www.avast.com" rel="nofollow" target="_blank">avast.com</a>) is its feature that you can schedule a virus scan at boot-time which I found very effective for removing viruses that hooks themselves on the start-up of windows. AVG (<a href="http://free.avg.com" rel="nofollow" target="_blank">free.avg.com</a>) and AVIRA (<a href="http://www.avira.com" rel="nofollow" target="_blank">avira.com</a>) are the two anti-virus replacements I used when AVAST fails.</p>
<p><a href="http://www.bleuken.com/free-tools-virus-worm-malware-20081120/">Free Tools for Virus, Worm, Malware &#038; Spyware Prevention &#038; Removal</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>


<p>Related posts:<ol><li><a href='http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/' rel='bookmark' title='Removal and Prevention of Gumblar.cn Infections'>Removal and Prevention of Gumblar.cn Infections</a></li>
<li><a href='http://www.bleuken.com/conficker-worm-virus-removal-and-prevention-20090121/' rel='bookmark' title='Conficker Worm/Virus, Removal and Prevention'>Conficker Worm/Virus, Removal and Prevention</a></li>
<li><a href='http://www.bleuken.com/malware-that-hijacks-google-adsense-20080715/' rel='bookmark' title='Malware that Hijacks Google &amp; Adsense'>Malware that Hijacks Google &#038; Adsense</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.bleuken.com/free-tools-virus-worm-malware-20081120/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced (User agent is rejected)
Object Caching 857/925 objects using disk: basic

Served from: www.bleuken.com @ 2012-02-11 00:20:20 -->
