Support

Admin Tools

#11940 "quarantined by Anti-virus software as "decode regex" detected in those files"

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Thursday, 12 April 2012 02:11 CDT

user6022
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? No
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 1.5.26
PHP version: 5.2.9
MySQL version: 5.0.95-community
Host: Linux
Admin Tools version: 2.2.5

Description of my issue:
I was advised by my Hosting company.

FYI, today some files of "BLOCKED" account are auto quarantined by Anti-virus software as "decode regex" detected in those files.
--------------------------------------------------------------------------------------------------------------------------------------------
# (quarantined to /backup/cXsQuarantine/scan/BLOCKED/chronocontact.html.php.1333971753_1) Regular expression match = [decode regex: 1]:
'/home/BLOCKED/public_html/components/com_chronocontact/chronocontact.html.php'
# (quarantined to /backup/cXsQuarantine/scan/BLOCKED/cf_Authorize_dotnet.php.1333971753_1) Regular expression match = [decode regex: 1]:
'/home/BLOCKED/public_html/components/com_chronocontact/plugins/cf_Authorize_dotnet.php'
# (quarantined to /backup/cXsQuarantine/scan/BLOCKED/cf_paypal_api.php.1333971754_1) Regular expression match = [decode regex: 1]:
'/home/BLOCKED/public_html/components/com_chronocontact/plugins/cf_paypal_api.php'
# (quarantined to /backup/cXsQuarantine/scan/BLOCKED/jfscan.php.1333951107_1) Regular expression match = [n(?!s*(//|#|*)).*/etc/passwd]
'/home/BLOCKED/public_html/administrator/components/com_admintools/akeeba/platform/jfscan/engines/archiver/jfscan.php'
--------------------------------------------------------------------------------------------------------------------------------------------

nicholas
Akeeba Staff
Manager
All of those files are legitimate PHP files. Your host has no business modifying your site's files without your consent. Basically, they broke your site. I don't know how am I expected to help you with a hosting issue?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user6022
Thanks Nicholas,

Thanks for the quick response.

My host is very good and will restore the files immediately. I would rather they are a little proactive in regards to this type of issue then not.

Regards
Redmonds

nicholas
Akeeba Staff
Manager
Well, I'd prefer if my host earned me instead of removing files matching a regex. I mean, regex matching is exactly how Admin Tools PHP File Change Scanner's Threat Score assessment works. Imagine what would happen if I arbitrarily deleted files with a threat score over 300 (that's pretty much what your host does): there would be a massive outcry from users about my software screwing up their sites. But in the end of the day it's your site and if you're OK with a semi-regular need to restore files from a backup when your host deletes them, that's fine with me :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!