• My dad’s site was recently hit with a trojan.js.redirector.cq virus and I’ve been troubleshooting how to fix the problem. His site is run on WordPress 3.0. Him and the vast majority of the visitors to his website use Windows, and I use Mac OSX.

    I found a forum explaining how to terminate the virus, but there are a few things I can’t figure out:
    1. change the db password
    – i can see the db info in the wp-config.php, so does that mean I could just swap out the password in dreamweaver and upload to the ftp?
    2. change the ftp password
    – i’ve been looking on different forums for a way to change the password, but have not found anything yet. i am using the newest version of Filezilla (3.3.3).

    I’m a designer, not a developer, so please keep it simple.

    Thanks for your help

Viewing 15 replies - 1 through 15 (of 28 total)
  • To change the database password, you need to change it at your hosting service as well as in wp-config.php, or else WordPress won’t be able to connect to the database. Look in your hosting control panel for how to change the database password. For the FTP password, you need to also go to your hosting control panel.

    Don’t use dreamweaver to edit text files. On OS X, use Textedit.

    See How to completely clean your hacked wordpress installation and How to find a backdoor in a hacked WordPress. Check for other administrators in WordPress users. Have him scan his WIndows PC for malware such as keyloggers.

    Thread Starter RyanNeil

    (@ryanneil)

    His previous designer/coder is MIA and my dad doesn’t know any of the hosting information. I looked up the db host in the wp-config.php file and it says:
    $_ENV{DATABASE_SERVER}

    Is there a way I can find out who is hosting his site?

    Thanks

    Do a whois search – enter the name and the host should show up:

    https://ismyblogworking.com/

    https://www.dnsstuff.com/?ptype=free

    That $_ENV{DATABASE_SERVER} is not the standard way to call a database server in wp-config.

    You’re probably also going to need the domain registrar. Use the links above or post your URL here.

    Thread Starter RyanNeil

    (@ryanneil)

    Okay, looks like his hosting is through Media Temple. If I can’t get ahold of his previous designer, who most likely has this site under his account, is it possible to be able to get the login information?

    His website is – post911foundation.org

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    ?????? Advisor and Activist

    If your father pays for the account with his credit card, yes. You can call for help, just have that card info handy!

    The domain is registered to Tier One Solutions, LLC 5705 Interbay Bvd, Tampa, FL. Is that you?

    Thread Starter RyanNeil

    (@ryanneil)

    That’s his security company. That means he must have the login info tucked away somewhere.. I’ll have to bug him to look for it again.

    Thanks for your help guys

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    ?????? Advisor and Activist

    He may not have the login info.

    Remember: Domain registration DOES NOT always equal Hosting info.,

    You want Web Host info, which you said was Media Temple. Who pays media temple? They can get you into your server and, thus, your wordpress database, where you can get your admin access etc.

    Thread Starter RyanNeil

    (@ryanneil)

    Ok, I got the info from him. I can log into his account through Network Solutions, but I’m not sure on how to change the db password from there.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    ?????? Advisor and Activist

    I don’t think you can, unless NetSol has the database. They’re the registrar, it sounds like.

    If MEDIA TEMPLE is your Web Host, THEY have the database.

    And you want to do this: https://codex.www.ads-software.com/Resetting_Your_Password

    Get into the media temple account.

    (FYI, some people have their host be their registrar, others don’t, which is why I feel it’s important to make sure you get the web host login info)

    Domain registration and hosting are separate in many cases, and in your case, they are, as your domain is registered at NetSol, but the namesrvers there point to Media Temple, which is the hosting.

    Thread Starter RyanNeil

    (@ryanneil)

    Hey Guys,

    Sorry it’s taken so long to get back, but I’ve been waiting to hear back from Media Temple.. There’s a bigger issue now though. When I try to pull up the website I get this error, both from the site and the back end admin for wordpress:
    Forbidden
    You don’t have permission to access /wp-admin on this server.
    Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.
    Apache/2.0.54 Server at post911foundation.org Port 80

    I have no clue what that could be from.. Any ideas?

    Thanks for your help

    Either the directory permissions were changed for some reason, or your whole site is gone. The files might have been wiped by Media Temple if your hosting account was closed or becuase of the malware. Your database might still be there.

    Thread Starter RyanNeil

    (@ryanneil)

    Damn..

    I called them a few days ago, but they wouldn’t give me any information because my name wasn’t on the account. They told me they would email my father with the account info, but they still haven’t done that yet.

    It would probably be best to call them after I get that info to help resolve the issue, right?

Viewing 15 replies - 1 through 15 (of 28 total)
  • The topic ‘Killing a Virus’ is closed to new replies.