at {web site} get js/downloader.agent ..from avg ..what kind of scripting would allow this

Posted on 2008-06-17
Last Modified: 2013-11-19
I go to {link removed} and  avg pops up with detect of js/downloader.agent warning with "ignore, heal, ignore"...then page freezes...and cannot get rid of page.  In internet explorer 7 the yellow status line comes up and says "Microsoft office 2000 web component is attempting to install an addon from an unverified publisher"..What script would cause this..does not appear on a mac running firefox.

{ links removed by PenguinMod, EE Moderator - 2008-06-17 1640 ET }
Question by:greta13
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 70

Expert Comment

by:Jason C. Levine
ID: 21806607
Hi greta13,

It's a "drive-by download" script that is trying to exploit a vulnerability in IE/Active X.  Stay away from that site...

Author Comment

ID: 21806668
I have to get to the bottom of it for the owner of the site who has hired people to build these files..for him..that script is on site "right?"...what should i look for when i access his files...I don't have access to the site right now but after I talk to the owner

Author Comment

ID: 21806699
I know html and basic php and javascrip..but now advanced enough to know what this might look like..
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

LVL 70

Accepted Solution

Jason C. Levine earned 500 total points
ID: 21806779
The code is a javascript tag located directly inside the <body> tag.  When evaluated, it creates an iframe that visits the hacker site and attempts to load the malware.  This site has been compromised and you need to take a series of steps immediately.

1. Check all of your pages for the code.
2. Change all passwords immediately
3. Notify the hosting company that you've been hacked and see if their security people can check their end of things.
4. Examine or pay a security consultant to examine all scripts for vulnerabilities.

Author Comment

ID: 21806879
just one more clarification..the iframe that pushes you to the that local to the web server or could that be another address off the server..thanks for your help
LVL 70

Expert Comment

by:Jason C. Levine
ID: 21806897
It most likely is remote, but I would have to actually let it evaluate to see it and I'm not willing to do that.
LVL 12

Expert Comment

ID: 21807212
For the HTML, take a look here (clean):

As you can see, there is a script element immediately following the body tag.  That's the problem.

Featured Post

MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Today, the web development industry is booming, and many people consider it to be their vocation. The question you may be asking yourself is – how do I become a web developer?
This article investigates the question of whether a computer can really be cleaned once it has been infected, and what the best ways of cleaning a computer might be (in this author's opinion).
The viewer will learn the basics of jQuery, including how to invoke it on a web page. Reference your jQuery libraries: (CODE) Include your new external js/jQuery file: (CODE) Write your first lines of code to setup your site for jQuery.: (CODE)
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question