By John Davis on Wednesday, 06 February 2019
Posted in General Issues
Replies 14
Likes 0
Views 605
Votes 0
Maldet reports a trojan in /home/worldexotic/public_html/media/com_easyblog/scripts/admin-5.2.11.min.

How can I download a clean version of that file so I can replace it?

Thanks
Hey John,

May I know what is the exact notice message shown and also what is the cause of their report?
·
Wednesday, 06 February 2019 14:22
·
0 Likes
·
0 Votes
·
0 Comments
·
Excacly the same error to me from imunify360 for files
scripts/admin-5.2.11.min
scripts/site-5.2.11.min
scripts/composer-5.2.11.min
·
Wednesday, 06 February 2019 17:12
·
0 Likes
·
0 Votes
·
0 Comments
·
FILE HIT LIST:
{CAV}Txt.Trojan.Coinminer-6840768-0 : /home/worldexotic/public_html/media/com_easyblog/scripts/admin-5.2.11.min.js => /usr/local/maldetect/quarantine/admin-5.2.11.min.js.1462921066
{CAV}Txt.Trojan.Coinminer-6840768-0 : /home/worldexotic/public_html/media/com_easyblog/scripts/composer-5.2.11.min.js => /usr/local/maldetect/quarantine/composer-5.2.11.min.js.1402614071
{CAV}Txt.Trojan.Coinminer-6840768-0 : /home/worldexotic/public_html/media/com_easyblog/scripts/site-5.2.11.min.js => /usr/local/maldetect/quarantine/site-5.2.11.min.js.160656954
·
Thursday, 07 February 2019 04:21
·
0 Likes
·
0 Votes
·
0 Comments
·
I believe all of these are false positive. The minified script file is simply just a collection of all the uncompressed files.
·
Thursday, 07 February 2019 11:47
·
0 Likes
·
0 Votes
·
0 Comments
·
I have had EB installed for almost a year, but the warnings have only just started a couple of days ago.
·
Thursday, 07 February 2019 22:02
·
0 Likes
·
0 Votes
·
0 Comments
·
It is very difficult for me to tell you what is going on if there are no logs or information about what it is reporting about. It's like finding a needle in a haystack. The minified file only contains a compressed file of all the scripts in the extension.

It does not matter if you have it installed for over a year or over 10 years because all these reports are checked against a central database where it could be pinpointing to some false positive report because of an older jquery install etc. Having said that, we will investigate and figure this out.

What antivirus tool do you have so that we can try running this scan as well
·
Thursday, 07 February 2019 23:45
·
0 Likes
·
0 Votes
·
0 Comments
·
We have just ran this scan thoroughly through:

1. The package that we downloaded from our site.

2. The single click updater

We did not receive any information about viruses from ClamAV. This is the result:

[gist]
[~/Desktop]$ clamscan -r -v 5.2.11
Scanning 5.2.11/scripts/site-5.2.11.min.js
5.2.11/scripts/site-5.2.11.min.js: OK
Scanning 5.2.11/scripts/composer-5.2.11-basic.min.js
5.2.11/scripts/composer-5.2.11-basic.min.js: OK
Scanning 5.2.11/scripts/site-5.2.11-basic.min.js
5.2.11/scripts/site-5.2.11-basic.min.js: OK
Scanning 5.2.11/scripts/composer-5.2.11.min.js
5.2.11/scripts/composer-5.2.11.min.js: OK
Scanning 5.2.11/scripts/admin-5.2.11-basic.min.js
5.2.11/scripts/admin-5.2.11-basic.min.js: OK
Scanning 5.2.11/scripts/admin-5.2.11.min.js
5.2.11/scripts/admin-5.2.11.min.js: OK
Scanning 5.2.11/stylesheets/admin/default/style-5.2.11.min.css
5.2.11/stylesheets/admin/default/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/elegant/style-5.2.11.min.css
5.2.11/stylesheets/site/elegant/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/elegant/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/elegant/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/hako/style-5.2.11.min.css
5.2.11/stylesheets/site/hako/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/hako/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/hako/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/radium/style-5.2.11.min.css
5.2.11/stylesheets/site/radium/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/radium/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/radium/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/altium/style-5.2.11.min.css
5.2.11/stylesheets/site/altium/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/altium/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/altium/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/carbon/style-5.2.11.min.css
5.2.11/stylesheets/site/carbon/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/carbon/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/carbon/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/plain/style-5.2.11.min.css
5.2.11/stylesheets/site/plain/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/plain/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/plain/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/timeless/style-5.2.11.min.css
5.2.11/stylesheets/site/timeless/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/timeless/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/timeless/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/lithium/style-5.2.11.min.css
5.2.11/stylesheets/site/lithium/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/lithium/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/lithium/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/origami/style-5.2.11.min.css
5.2.11/stylesheets/site/origami/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/origami/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/origami/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/vintage/style-5.2.11.min.css
5.2.11/stylesheets/site/vintage/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/vintage/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/vintage/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/wireframe/composer-5.2.11.min.css
5.2.11/stylesheets/site/wireframe/composer-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/wireframe/style-5.2.11.min.css
5.2.11/stylesheets/site/wireframe/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/wireframe/composer-5.2.11-rtl.min.css
5.2.11/stylesheets/site/wireframe/composer-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/wireframe/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/wireframe/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/bluedream/style-5.2.11.min.css
5.2.11/stylesheets/site/bluedream/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/bluedream/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/bluedream/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/cobalt/style-5.2.11.min.css
5.2.11/stylesheets/site/cobalt/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/cobalt/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/cobalt/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/pastel/style-5.2.11.min.css
5.2.11/stylesheets/site/pastel/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/pastel/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/pastel/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/stackers/style-5.2.11.min.css
5.2.11/stylesheets/site/stackers/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/stackers/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/stackers/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/nomad/style-5.2.11.min.css
5.2.11/stylesheets/site/nomad/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/nomad/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/nomad/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/dark/style-5.2.11.min.css
5.2.11/stylesheets/site/dark/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/dark/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/dark/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/bubbles/style-5.2.11.min.css
5.2.11/stylesheets/site/bubbles/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/bubbles/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/bubbles/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/zinc/style-5.2.11.min.css
5.2.11/stylesheets/site/zinc/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/zinc/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/zinc/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/nickel/style-5.2.11.min.css
5.2.11/stylesheets/site/nickel/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/nickel/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/nickel/style-5.2.11-rtl.min.css: OK
Scanning 5.2.11/stylesheets/site/simplistic/style-5.2.11.min.css
5.2.11/stylesheets/site/simplistic/style-5.2.11.min.css: OK
Scanning 5.2.11/stylesheets/site/simplistic/style-5.2.11-rtl.min.css
5.2.11/stylesheets/site/simplistic/style-5.2.11-rtl.min.css: OK

----------- SCAN SUMMARY -----------
Known viruses: 6800143
Engine version: 0.101.1
Scanned directories: 27
Scanned files: 51
Infected files: 0
Data scanned: 41.28 MB
Data read: 19.27 MB (ratio 2.14:1)
Time: 18.174 sec (0 m 18 s)
[/gist]
·
Friday, 08 February 2019 11:05
·
0 Likes
·
0 Votes
·
0 Comments
·
I don't want to try to analyze the reason the file may or may not contain malware. I just want to download and replace with a clean version on my server. If Maldet doesn't find a problem, I'll know my file was hacked. If it does find a problem with the new file, I'll know it;s a false positive and will add to the ignore list.
·
Friday, 08 February 2019 22:31
·
0 Likes
·
0 Votes
·
0 Comments
·
We ran many tests locally and we came to a conclusion that this is a false positive. On another customer site, when their hosting company updated their virus database, these warnings are gone.

Please check with your hosting company to update their anti virus database.
·
Saturday, 09 February 2019 14:38
·
0 Likes
·
0 Votes
·
0 Comments
·
Why can't I simply download the file?
·
Saturday, 09 February 2019 23:12
·
0 Likes
·
0 Votes
·
0 Comments
·
cant you download latest new EasyBlog and take out that file from EasyBlog ? com_easyblog/scripts/admin-5.2.11.min ??
·
Sunday, 10 February 2019 17:53
·
0 Likes
·
0 Votes
·
0 Comments
·
We have 5 customers site confirming that this is a false positive when they re-ran the scan with their cpanel when their hosts updated their virus database.

I am pretty sure this is a false positive with Maldet as well so I would suggest that you update Maldet's virus definition list and run the scan again.
·
Monday, 11 February 2019 10:34
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post