Google Groups Home
Help | Sign in
Discussions > Suggestions & feature requests -- webmaster-related only, please > Website link on Googles links to trojan.exploit.131
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 50 - Collapse all   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
kwkcae  
View profile
 More options Aug 21 2007, 8:50 am
From: kwkcae
Date: Tue, 21 Aug 2007 05:50:47 -0700
Local: Tues, Aug 21 2007 8:50 am
Subject: Website link on Googles links to trojan.exploit.131
When I search Google for my website, I enter Jonathan Wentworth
Associates.

As expected, the site appears at the top of the list.
When I click the URL link at the end of the entry it takes me to the
site.

However, when I click on the "title" link at the top of the entry it
re-routs "people" through to a different URL in seconds and to the
trojan.exploit.131 Trojan.  If they do not have the latest McAfee or
Norton it downloads the Trojan to their computer.  McAfee and Norton
seems to clean it but our concern is for those who are not real savvy
or as committed to keeping their virus protection software up to date.

I assume I have no control over this and it seems there is no real way
to contact anyone at Google to find out how to fix this problem.

Any suggestions?

Thank you


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu  
View profile
 More options Aug 21 2007, 10:14 am
From: JohnMu
Date: Tue, 21 Aug 2007 14:14:39 -0000
Local: Tues, Aug 21 2007 10:14 am
Subject: Re: Website link on Googles links to trojan.exploit.131
You need to report it to stopbadware.org: http://stopbadware.org/home/story

John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu  
View profile
 More options Aug 21 2007, 10:23 am
From: JohnMu
Date: Tue, 21 Aug 2007 14:23:57 -0000
Local: Tues, Aug 21 2007 10:23 am
Subject: Re: Website link on Googles links to trojan.exploit.131
Sorry, I'm not sure that I understand you completely ...

Which entries are you clicking on? Is it something on your site?
Someone else's site?

John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cristina  
View profile
 More options Aug 21 2007, 11:38 am
From: cristina
Date: Tue, 21 Aug 2007 08:38:34 -0700
Local: Tues, Aug 21 2007 11:38 am
Subject: Re: Website link on Googles links to trojan.exploit.131
As John wrote, maybe give more details.
Do you mean the results in a google.com search?
I still do not understand what links you mean,
which is the wrong one and which is the
correct one.

You should be able to see the URL
in the status bar of the browser when you hover over a link,
without clicking on the link.

Is the URL pointing to the trojan malware URL from your site?

You can see the exact URLs of links in a Google
search result page if you look at that page
with 'view source' from your browser.

Cristina.

On Aug 21, 1:50 pm, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
 More options Aug 21 2007, 12:15 pm
From: djc
Date: Tue, 21 Aug 2007 09:15:39 -0700
Local: Tues, Aug 21 2007 12:15 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
It sounds like your site was hacked.  What you need to do is clean it
up.  Look for changes in .htaccess (or the addition of such a file in
any and all folders - web.config if you are on a windows server).
Also check your cgi-bin and notify your hosting provider once you find
any altered files.  If you do not find any, than still contact your
hosting provider so they can see what method is being used to redirect
from your URL's to the malware site.

On Aug 21, 7:50 am, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
 More options Aug 21 2007, 12:17 pm
From: djc
Date: Tue, 21 Aug 2007 09:17:49 -0700
Local: Tues, Aug 21 2007 12:17 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
BTW - DO NOT follow the link for www.jwentworth.com - that will
redirect to an IP that will try and install the trojan.

On Aug 21, 7:50 am, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
 More options Aug 21 2007, 12:19 pm
From: djc
Date: Tue, 21 Aug 2007 09:19:41 -0700
Local: Tues, Aug 21 2007 12:19 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
When I check for the 301 pretending to be Google, nothing happens
which is probably the reason why the site hasn't been flagged yet.

On Aug 21, 7:50 am, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
kwkcae  
View profile
 More options Aug 21 2007, 2:16 pm
From: kwkcae
Date: Tue, 21 Aug 2007 11:16:35 -0700
Local: Tues, Aug 21 2007 2:16 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
OK I will try again :-)

When I do a google search for Jonathan Wentworth Associates the first
result is:

Jonathan Wentworth Associates, LTD Welcome to Jonathan Wentworth
Associates, a respected resource for world-class orchestral soloists,
conductors, opera, chamber music, chamber orchestras, ...
www.jwentworth.com/ - 19k - Cached - Similar pages - Note this

The: Jonathan Wentworth Associates, LTD is highlighted and is a link
to the web site.  If you place the mouse over the link, it shows
http://www.jwentworth.com.  However, if you click the link it
immeately attempts to download the trojan.  My McAfee immediatly
blocked it.

Does that help?

Thank you

On Aug 21, 8:50 am, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cristina  
View profile
 More options Aug 21 2007, 2:32 pm
From: cristina
Date: Tue, 21 Aug 2007 11:32:27 -0700
Local: Tues, Aug 21 2007 2:32 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
Check the source of your code at that URL
and ask your web hosting provider to do a
thorough check.

Could be something to do with your computer?

Cristina.

On Aug 21, 7:16 pm, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cristina  
View profile
 More options Aug 21 2007, 2:38 pm
From: cristina
Date: Tue, 21 Aug 2007 11:38:43 -0700
Local: Tues, Aug 21 2007 2:38 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
To repeat what Dori wrote,
do not follow or check
the link to that URL.

It is possible that it depends on the user agent
and it is malware when the user agent is a browser
and not a bot.

You have to ask your web hosting provider
to check this thoroughly and remove what
corresponds now on the server to this URL
and to check if there is other malware.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
kwkcae  
View profile
 More options Aug 21 2007, 8:15 pm
From: kwkcae
Date: Tue, 21 Aug 2007 17:15:16 -0700
Local: Tues, Aug 21 2007 8:15 pm
Subject: Re: Website link on Googles links to trojan.exploit.131
Thank you all.

We will see what we can find.
Just as info for you we downloaded the entire site to our computer and
did a virus scann and found nothing in the pages or cgi-bin
materials.  We also checked the page completely for redirects tht
could have been hidden and found nothing.

We are going to approach the web host about this.

Though we are still not sure where we are - Again thank you for all
your help.

kwkcae

On Aug 21, 2:38 pm, cristina wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
(1 user)  More options Aug 22 2007, 3:54 am
From: djc
Date: Wed, 22 Aug 2007 00:54:59 -0700
Local: Wed, Aug 22 2007 3:54 am
Subject: Re: Website link on Googles links to trojan.exploit.131
The trojan isn't in your pages.  When calling your domain, a process
activates that redirects the user to an IP address which then;

1: puts up a fake McAffee Screen
2: attempts to auto install the trojan
3: has a message telling users to basically "click here" to start the
download to protect themselves.  The download is yet another virus.

It sounds to me like you are clueless on how these things work.  You
need to contact your hosting provider.

On Aug 21, 7:15 pm, kwkcae wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tjfx  
View profile
 More options