Announcement

Collapse
No announcement yet.

Virus Check

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Virus Check

    I have been emailed by the owner of a website that is on the same server as my site (shared server hosting) asking:
    "I just wondered if any of your users have reported a problem with your website redirecting them to a site telling them they have a virus. We host a site on the same server as yourselves and can't determine whether our site has been hacked or the server and hence every site has been infected"
    I have checked my site on two PC's and using all the major browsers and cannot find any problems or receive any errors, although in the last couple of weeks I have receieved two reports from customers:

    1. Paid for order on telephone as he said adverts popped up when trying to pay.
    2. Phoned through order as said rececived a warning message of some sort when she visited the homepage.

    It is possiboe that one/both these customers had either some over zealous software or had spyware or viruses on their own PC's unrelated to my site.
    Google had not reported any problems and Google Analytics doesn't seem to show any increase in bounce rates, etc.

    I am fairly confident that my site is virus free but would appreciate it if a few fellow forum readers could browse my site and confirm that they also don't receive any virus warnings, etc to put my mind at rest.
    Darren Guppy
    Golf Tee Warehouse
    Golf Tees and Golf Accessories.

    #2
    You do have problems Darren - I browsed (using IE8) and all of a sudden I was redirected to a site (url below) then the page disappeared and I got a pop up (screenshot attached) telling me to use Total Security to scan my computer. I'm not sure what page I was on when the redirect kicked in I'm afraid and can't recreate the issue.
    I have Norton 360 and am positive my system is clear by the way.
    Edit:
    this is the url I was redirected to (the url doesn't work now) http://winfixscanner9.com/scan1/?pid...EyNTE1MMcOOAkN
    Attached Files
    Last edited by meden; 21-Sep-2009, 01:09 PM. Reason: More info added
    The Pretty Dress Company

    Comment


      #3
      I have browsed your site using FFv3 and IE7 - no problems going through section, catalog and CGI URL's, added to cart with no problems.


      Just tried Opera.

      Got to the home page, then clicked Golf Tees and then the first Sub-Section.

      The requested URL could not be retrieved

      While trying to retrieve the URL:

      http:// winfixscanner9. com/scan1/?pid=
      180s1&engine=%3DXm49DTuMzkuMTU4LjExNiZ0a
      W1lPTEyNTc1MMgONAkO (I've broken the URL)

      The following error was encountered:

      Access to requested object is forbidden
      Generated:
      Mon Sep 21 14:14:31 2009
      Kaspersky Internet Security 2009

      Comment


        #4
        Thanks,

        I now had further information from the webiste owner on the shared server (non actinic site)

        The problem manifests itself in trying to redirect the user to a site called delete-all-virus09.com or similar (it seems to morph over time). At this time it drops a cookie onto the users pc from nationaltreasure.cn. I'm not sure what the cookie is doing at present but I supect that the malicious redirect checks to see if this cookie is present and acts differently depending on what it finds.

        The redirects occur very infrequently, possibly once in any 12 hour period for any user and seem to be from random links on the site and not just the home page.

        If the user doesn't have up to date AV software then the site that the user is redirected to installs a false AV scanner and prompts the user to buy some software to get rid of the supposed infection.

        Users with Firefox seem not to be affected.

        We have done a fresh install of the software on the site which didn't cure the problem which tends to make me think its a server thing rather than being site specific but I can't be 100% certain.

        I'll keep you posted as to what happens
        Darren Guppy
        Golf Tee Warehouse
        Golf Tees and Golf Accessories.

        Comment


          #5
          Originally posted by Golf Tee Warehouse View Post
          If the user doesn't have up to date AV software then the site that the user is redirected to installs a false AV scanner and prompts the user to buy some software to get rid of the supposed infection.
          I don't think it's the users av software being out of date thats the problem - mine is bang up to date, probably down to the browser settings allowing more than is sensible I suppose
          The Pretty Dress Company

          Comment


            #6
            Total security is a rogue program, that once installed will install other forms of adware and spyware on your pc.

            they scare the user into acting upon a false threat. e.g. a pop says you have been infected and they need to click ok to remove the threat, but in doing so they are install the threat. crafty buggers.
            "If my answers frighten you then you should cease asking scary questions"

            Comment


              #7
              So far I have checked the source code of the webpages and can't see anything obvious to cause the problem (including searching for iframes).

              I have downloaded a copy of the entire site (zipped backup through cpanel), unzipped it and am now performing various anti-virus / malware checks on the downloaded files and the whole PC.

              I have also changed my ftp password.
              Darren Guppy
              Golf Tee Warehouse
              Golf Tees and Golf Accessories.

              Comment


                #8
                ftp to your website and delete everything, then re upload, ie8 is an automatic update for all those windows users with it turned on so alot of your customers are going to get the warning and when some of these click it they will be pretty pee'd with you when they get a keylogger/spyware or a virus

                Comment


                  #9
                  Should I delete just the CGI-BIN and acatalog folders?

                  When I browse the site using IE8 or Opera I get no error messages.
                  Darren Guppy
                  Golf Tee Warehouse
                  Golf Tees and Golf Accessories.

                  Comment


                    #10
                    I have deleted the cgi-bin and acatlog folders and uploaded the site again, but on first visit using IE7 I got redirected when trying to checkout.

                    I have not yet found a virus and am still going through a series of virus / malware checks with several bits of software.

                    Do I need to delete other folders/files on the server.

                    Should I be able to see the cause of the re-direction in the source code of a page, as I have looked and can not see anything.
                    Darren Guppy
                    Golf Tee Warehouse
                    Golf Tees and Golf Accessories.

                    Comment


                      #11
                      When I was redirected I was initially redirected to www dot readcnn2 dot com before redirecting to winfixscanner9 dot com and a cookie was placed on PC called darren@read-cnn2.com.
                      Darren Guppy
                      Golf Tee Warehouse
                      Golf Tees and Golf Accessories.

                      Comment


                        #12
                        i would check the files you have at the root of the site too. ie yourdomain/index.html

                        also delete the contents of 2 folders on your PC - siteHTML and preveiwHTML (they are within site1)

                        malwarebytes is agood proggie for tracking down spyware etc on your pc.

                        if you have deleted the entire acatalog folder, dont forget to reset the order number in troubleshooting menu otherwise you might return to 00001.

                        Comment


                          #13
                          Thanks Jo,

                          I will delete the contents as described.

                          Malwarebytes is currently running a full-scan as I type. The first quick scan earlier today found 4 problems which it fixed and a later quick scan was all clear.

                          P.S. You were correct about the order number resetting to zero.
                          Darren Guppy
                          Golf Tee Warehouse
                          Golf Tees and Golf Accessories.

                          Comment


                            #14
                            Who are you hosted with? I presume you have told them of the problem as it does seem strange that 2 sites on the same server have been affected (infected!). If malwarebytes doesn't find anything specific to your site then it's more likely to be a server problem. Hope you get it sorted soon.
                            www.silvermoonbeads.com - Gemstones, Pearls, Hill Tribe sterling silver, Swarovski and Findings.

                            Comment


                              #15
                              Sorry to hear of your probs Darren.
                              We were on shared hosting with UKFast and we had our .htaccess file hacked by some low life.
                              Then we started having our emails returned by hotmail and others as the IP address was obviously blacklisted.
                              We contacted UKFast and to their credit they did sort it out and have the blacklisting removed, but it came back again after a couple of weeks.
                              It's these two things that finally pushed us to go for a Dedicated server; now we are in complete control of what's on our IP address and a suitably long, boring (and difficult-to-remember!) password makes it pretty secure.
                              It is more expensive of course, but what price peace of mind, not to mention no more wasted time. And our websites now go like lightning
                              Kind Regards
                              Sean Williams

                              Calamander Ltd

                              Comment

                              Working...
                              X