1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus om my website!

Discussion in 'Security and Privacy' started by Tore, 2004/05/10.

Thread Status:
Not open for further replies.
  1. 2004/05/10
    Tore

    Tore Inactive Thread Starter

    Joined:
    2003/04/10
    Messages:
    20
    Likes Received:
    0
    Visitors to my website tell me that a Redlof virus is on my website!

    When I download the webpages to my computer and performs a virus scan on these pages no virus is detected!

    It almost seems pointless to upload new pages since the pages I downloaded appear to be virus free, or what?

    Does anybody know how to get rid of this problem?
     
    Tore,
    #1
  2. 2004/05/10
    Pondlife

    Pondlife Inactive

    Joined:
    2003/07/09
    Messages:
    80
    Likes Received:
    0
    Who is hosting your webspace? Might be worth asking them to scan the server your site is sitting on to see if the virus is actually on the box rather than just within your website/space??
     

  3. to hide this advert.

  4. 2004/05/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You'll need to look in the source code for something added. Private Message me a link and I'll check it out.
     
  5. 2004/05/10
    rcerrato

    rcerrato Inactive

    Joined:
    2002/01/07
    Messages:
    155
    Likes Received:
    1
    Post the URL of this site so we can take a look.
     
  6. 2004/05/10
    Tore

    Tore Inactive Thread Starter

    Joined:
    2003/04/10
    Messages:
    20
    Likes Received:
    0
    I want to make sure my pages are 100% clean first and if problem persists I will contact my ISP.
     
    Tore,
    #5
  7. 2004/05/11
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    If any pages on your Host's server (that you uploaded) have this virus then realize that the infection is on YOUR computer and these html files got infected prior to you uploading them.

    http://securityresponse.symantec.com/avcenter/venc/data/html.redlof.a.html

    Also, people who have told you that your website is infected may in fact not understand how this virus functions, and they may be infected, in fact every website they visit will "appear" to be infected with this virus because the virus searches out all html files on the computer (including the Temp Internet Files) and will infect them. Thus if they are infected, all of their html files will get attacked by the virus.
     
    Last edited: 2004/05/11
  8. 2004/05/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yep, it's infected. Homepage contains VB script, ActiveX component. If you view source on the page you will see it all the way at the bottom. Should be able to edit it out. I saved all the pages to my PC and scanned them with RAV. That was the only one found infected and the ones I checked, which was most of them, didn't have it. I can't debate with TonyT as to whether your PC is also infected and that is how the page got infected, because I just don't know. I know it's very possible that it was hacked in. And I don't believe you put it there intentionally or you would have posted the link for more exposure. :)

    RAV report.
    DFD® Technology PAT™ Precision pull off adhesion testers.htm->(SCRIPT0004) - VBS/ActiveXExploit* -> Infected
     
  9. 2004/05/11
    Tore

    Tore Inactive Thread Starter

    Joined:
    2003/04/10
    Messages:
    20
    Likes Received:
    0
    Well, thank you for all the help! I have deleted the script.

    Personally I don't think anyone would have hacked in and put this little script there but who knows? I think my machine was infected at some stage and then I would have uploaded that page to the webserver. The peculiar thing, though, is that when I virus-scanned the web folder on my PC no Redlof turned up.

    Would my PC be infected all over if I simply kept an infected version of the web page on the hard disk, or would I have to open the file to spread it? The vbscript code only had about 240 characters, not more than one could put in a text file cookie... Dreadful!

    Lately, certain search engine rankings for some very relevant terms and expressions have gone down from 1st and 2nd pos. to 39th with noticeable effect. (=less sales enquiries) Is it likely that search engines penalizes webpages with viruses? If so, I would have thought the search engines would delete the sites from the indexing altogether.
     
    Tore,
    #8
  10. 2004/05/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    A little more info on Redlof at Sophos. If you follow the link to Microsoft you will see that they issued a patch for the JVM vulnerability back in October of 2000. Really no good reason for anyone to get infected with this virus. :rolleyes:
     
  11. 2004/05/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Just saw your new post. Glad you got rid of it. My AVG on this machine didn't detect it either. Scan with RAV. :) As noted by TonyT, the virus searches out .htm on your drive and infects them also, so yes, if you had/have this infection it would probably be all over your drive. But like I said previously, I saved that infected page to my drive yet nothing else became infected. And as I stated also earlier, there's no excuse for getting infected since the patch was issued so long ago. At most, one would only get that one infected page in a TIF, and that's easy enough to get rid of. Sorry, but I can't answer your questions related to search engines and penalizations. No knowledge of that. :(
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.