Skip to main content

Friday the 13th, a bad-luck message JS/redir.BS for a wordpress website

JS/redir.BS is a malaware that silently is stored in your website and will cause something ugly to happen: lose access to it.

There is no simple way to know when it got there, but several places can give you a clue on how to get rid of it. Important advice: take care of your website security, create backups and change passwords every now and then! Wordpress is a strong tool, but not invensible.

As I know how to control my computer and get rid of malaware, I decided to create a simluation in my computer, that was risky, but the fastest way to do it instead of waiting for the hosting company to help me.
I did a clean installation of Wordpress last version, the one I use in my website.
As I was suspicious of the theme, that was the first thing I copied from the server to my laptop. When I tried to move the theme folder to my local Wordpress installation, there it was. My Antivirus poped-up and blocked the virus, luckily it was just in the header file.
If you still can access to wp-admin on your website, go to the infected file, and get rid of it or of the infected code. It is Javascript code.
Change your passwords, all of them. Do the same for the keys using the Wordpress generator and overwrite them at the wp-config file.

If your case was not that simple:
First, confirm if your website is infected with malaware: http://sitecheck.sucuri.net/scanner/
Second, make some good reading http://codex.wordpress.org/FAQ_My_site_was_hacked
And learn how to Completely clean your hacked wordpress: http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/

Either way, make sure your website is not infected http://sitecheck.sucuri.net/scanner/

Comments

Popular posts from this blog

Haz lo que te hace feliz

Xirimen es un ingeniero, artista innovador y talentoso. De origen ecuatoriano, vivió en Madrid desde los 3 años de edad, cuando su familia decidió poner rumbo y dar a los tres hermanos un mejor futuro. Xiri creció en un entorno familiar y lleno de cariño, con las dificultades que conlleva ser emigrante. Siempre ha sido un joven optimista y con un profunto talento artístico, que le llevó a formar parte del Cream Kingz/Madrid Kingz Flava como b-boy. Un arte que desarrolló desde los 13 años de edad. Xiri ingresó en una de las universidades de mayor prestigio en el ámbito de la ingeniería en España y Europa. Llevado por su pasión al sonido y a la música, estudió ingeniería en telecomunicaciones en la que obtuvo varios honores. Durante sus estudios, Xiri experimentó con Turquía en el programa de Erasmus Mundus. Y al graduarse, decidió ampliar sus conocimientos en el resto de Europa. Xiri-Men, cómo saliste tan innovador? tan maduro? tan alegre? tan inteligente?.....

Ya viene el niñito jugando entre flores...

Si eres ecuatoriano, seguro te disfrazaste de cholita/o o pastorcito o angelito o Virgen María o San José y escuchaste esta canción en los pases del niño, y recibías la bolsita de galletas burrito y caramelos...tradiciones hermosas.  

Home buying process, the real deal

One day you wake up and think "I'm gonna buy a house" And keep reasoning "it is time to use all the time and effort and savings in something more durable, a real investment". That one day for me meant almost two years of digging, reading, researching, saving and most importantly building my credit. Here's a summary of what I learned when I made a first try... Workshop - you'll need this in the future, make sure is HUD approved. It is a workshop that explains what you're about to start. I recommend this. It took me a few months, because I dedicated 8 minutes some days....I think it's intended to take you 8 hours. eHome America was the provider I chose, and I got a voucher for the free workshop from a non-profit that provides resources for new buyers. Counseling - After you complete the workshop, bring your certificate of completion and meet with a counselor. I chose to go to the same agency that gave me the voucher, because they already knew...