CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

How do I remove an infection/virus/malware from my website

 
Post new topic   Reply to topic       All -> FavForums -> Web 2.0 [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
moot

Cadet
Cadet


Joined: May 11, 2004
Posts: 7
Location: USA

PostPosted: Mon May 12, 2008 11:35 pm    Post subject: How do I remove an infection/virus/malware from my website
Reply with quote

I am the administrator of a small private school. Several users have reported malware on our school website that redirects them to a blog with negative info posted about the school. I have not been able to see this first hand, since the security on our network blocks whatever is causing the problem. We have tried working with our webhosting service (Ipower) who said there is nothing they can do and directed us to Google. Can anyone tell me what recourse we have? Thanks.

Back to top
View users profile Send private message
BigFelix
Warnings : 2

Captain
Captain
Premium Member

Joined: Mar 19, 2008
Posts: 506
Location: San Diego
Premium

PostPosted: Thu May 15, 2008 8:11 am    Post subject:
Reply with quote

Hello! I am not an authorized responder, but I am pretty sure that they will first direct you to http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction. Should that fail, you may then go on to Trend Micro HijackThis Logs (which, I believe, you availed yourself of several years ago). Best of luck.


_________________
The whole problem with the world is that fools and fanatics are always so certain of themselves, but wiser people so full of doubts.
    Bertrand Russell
Back to top
View users profile Send private message Send email
BigFelix
Warnings : 2

Captain
Captain
Premium Member

Joined: Mar 19, 2008
Posts: 506
Location: San Diego
Premium

PostPosted: Fri May 16, 2008 12:28 pm    Post subject:
Reply with quote

Could this possibly be a mean prank by a student; a competitor?


_________________
The whole problem with the world is that fools and fanatics are always so certain of themselves, but wiser people so full of doubts.
    Bertrand Russell
Back to top
View users profile Send private message Send email
RiBiNiN

Blue Angel
Staff Writer
Staff Writer

Joined: May 04, 2006
Posts: 463

Blue Security Premium Team F@H

PostPosted: Sun May 25, 2008 11:14 am    Post subject:
Reply with quote

The web hosting service is responsible for the security of the site and in fact CAN do something about it if there is malware on their server.

Can you describe more exactly what is happening? Why do you think they are referring you to Google (who won't be able to do anything about malware)?

The more precise you can be, the more we can help.


_________________
Websplasher website design. Design with a splash.
Back to top
View users profile Send private message Visit posters website
Blast

General
General
Premium Member

Joined: Sep 20, 2003
Posts: 5469

Premium Team F@H

PostPosted: Wed Jun 11, 2008 4:44 am    Post subject:
Reply with quote

Hi there moot

I am interested in your situation as it would appear that someone has accessed your site (with admin rights) and caused some mayhem.

This can usually be handled by removing the offending page (or pages)

If you can get someone to provide you with the links that the redirects happen from you should be able to access those pages from your Site Control Panel or FTP Client and replace them with pages that are clean

You web host would be able to help if you can give them the links the redirect happens from also

That will be the first step

From there, you will need to restrict the access and ramp up your security. Usually your sites control panel will have tools to help you with this and changing passwords will restrict access to the back end.

Hope this is a help in starting to clear it up


_________________
Blast aka Bill Gray
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web 2.0 All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer