Close

Results 1 to 14 of 14
  1. #1
    DF VIP Member
    Lou_smorals's Avatar
    Join Date
    Nov 2002
    Location
    UK
    Posts
    2,320
    Thanks
    743
    Thanked:        599
    Karma Level
    447

    Question village website (VIRUS?)

    Hi
    I maintain our village website, this was put together using Joolma 1 by myself (complete lamer) with some top help from big larry some years ago. (www.roughtonvillage.co.uk) today I have had a villager on the telephone upset that "your site is a virus." when I asked him to be more specific he said AVG says it came from the village site. when he goes to the website is says "webshield alert threat detected threat name: exploit search engine hijack."
    Please can somebody advise me if I have done something wrong and what I should tell the geezer.
    many thanks
    LS

  2. #2
    DF VIP Member Zippeyrude's Avatar
    Join Date
    Dec 2002
    Location
    UK
    Posts
    4,317
    Thanks
    238
    Thanked:        792
    Karma Level
    535

    Default Re: village website (VIRUS?)

    have you visited the site yourself with avg?

  3. #3
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: village website (VIRUS?)

    AVG really doesn't like this file - http://www.roughtonvillage.co.uk/tem...log_bullet.png

  4. #4
    DF VIP Member Zippeyrude's Avatar
    Join Date
    Dec 2002
    Location
    UK
    Posts
    4,317
    Thanks
    238
    Thanked:        792
    Karma Level
    535

    Default Re: village website (VIRUS?)

    summit on ur site is infected

    avg 8.5 screenshot attached

  5. #5
    DF VIP Member
    psxcity's Avatar
    Join Date
    Jan 2001
    Location
    london/s.wales
    Posts
    781
    Thanks
    72
    Thanked:        88
    Karma Level
    367

    Default Re: village website (VIRUS?)

    just done a quick visit and scan on that url got no warnings
    Checking: http://www.roughtonvillage.co.uk
    Engine version: 5.0.0.12182
    Total virus-finding records: 550079
    File size: 20.94 KB
    File MD5: 6c556bb29a3bc18b7e950525c21074aa

    http://www.roughtonvillage.co.uk - archive HTML
    >http://www.roughtonvillage.co.uk/JavaScript.0 - Ok
    >http://www.roughtonvillage.co.uk/JavaScript.1 - Ok
    >http://www.roughtonvillage.co.uk/JavaScript.2 - Ok
    >http://www.roughtonvillage.co.uk/javascript.3 - Ok
    http://www.roughtonvillage.co.uk - Ok

  6. #6
    DF VIP Member
    Lou_smorals's Avatar
    Join Date
    Nov 2002
    Location
    UK
    Posts
    2,320
    Thanks
    743
    Thanked:        599
    Karma Level
    447

    Default Re: village website (VIRUS?)

    Hi
    Wow, thank you all so much, so guy is correct! oh dear. what would u advise I do from here?
    thanks
    LS

  7. #7
    DF VIP Member Zippeyrude's Avatar
    Join Date
    Dec 2002
    Location
    UK
    Posts
    4,317
    Thanks
    238
    Thanked:        792
    Karma Level
    535

    Default Re: village website (VIRUS?)

    replace the file for presumably a clean one.

    is the folder native to the site or has it been added by a hack?

  8. #8
    DF VIP Member
    psxcity's Avatar
    Join Date
    Jan 2001
    Location
    london/s.wales
    Posts
    781
    Thanks
    72
    Thanked:        88
    Karma Level
    367

    Default Re: village website (VIRUS?)

    strange that avg picks it up and both my scans dont,even tried a online scan url to find it clean,anyone else picked a warning up using someting other than avg?

  9. #9
    DF VIP Member
    Lou_smorals's Avatar
    Join Date
    Nov 2002
    Location
    UK
    Posts
    2,320
    Thanks
    743
    Thanked:        599
    Karma Level
    447

    Default Re: village website (VIRUS?)

    hi
    Should I take it offline until fixed?
    thanks
    LS

  10. #10
    DF VIP Member iNSPECTA's Avatar
    Join Date
    Dec 2005
    Location
    UK
    Posts
    1,592
    Thanks
    231
    Thanked:        267
    Karma Level
    348

    Default Re: village website (VIRUS?)

    Clicking the link to the 'infected' blog bullet takes me to:
    Code:
    http://poshdates.com/photos/search.php?q=do%20it%20yourself%20bankruptcy

  11. #11
    DF VIP Member BigLarry's Avatar
    Join Date
    Sep 2003
    Location
    Gernston
    Posts
    262
    Thanks
    0
    Thanked:        0
    Karma Level
    270

    Default Re: village website (VIRUS?)

    The file wasn't infected, pretty sure you can't do that with a png anyway.

    Problem was that someone had basically pissed about with the htaccess in the templates directory redirecting any 404's to a php script which basically looks on the server you are referred to like someone has searched on the poshdates.com site for "do it yourself bankruptcy". As in the link below:

    http://poshdates.com/photos/search.p...f%20bankruptcy

    What perhaps happens next is that there's a fake javascript click on the site to boot on one of the links (they're all basically sponsered links).

    So the people paying for the "sponsered links" see what look like bona fide visitors going to the search box entering a term and clicking a link. They have a valid new user IP address, a referrer etc etc

    To sum it up, it's click fraud and not a virus

    Thoic - The friendly forums.

  12. #12
    DF VIP Member
    Lou_smorals's Avatar
    Join Date
    Nov 2002
    Location
    UK
    Posts
    2,320
    Thanks
    743
    Thanked:        599
    Karma Level
    447

    Default Re: village website (VIRUS?)

    Quote Originally Posted by BigLarry View Post
    The file wasn't infected, pretty sure you can't do that with a png anyway.

    <snip>
    To sum it up, it's click fraud and not a virus


    Thanks m8, you the man, Larry the 4rth emerency service, oh and u can shove thoic right up your farter.
    LS
    Xdigital was the place

  13. #13
    DF VIP Member Latic's Avatar
    Join Date
    Apr 2004
    Location
    England
    Posts
    613
    Thanks
    0
    Thanked:        10
    Karma Level
    291

    Default Re: village website (VIRUS?)

    Lou,

    You'll need to completely update your Joomla install to stop this happening again. Looks like someone has used an exploit with the old code.

  14. #14
    DF VIP Member c0axial's Avatar
    Join Date
    Feb 2002
    Location
    M44
    Posts
    1,493
    Thanks
    159
    Thanked:        188
    Karma Level
    382

    Default Re: village website (VIRUS?)

    Upgrade Joomla.... had the same issue when teamfury.co.uk got compromised with a sploit, ended up with a replaced php and a packaged virii ... sounds like the same issue ... the blighters scan hosts and find exploitable hosts.....they ended up putting political war images with blown up body parts.... Upgrade Upgrade Joomla ASAP...
    127.0.0.1

Similar Threads

  1. Cheapest website for Flash 2 Linker?
    By pfrench69 in forum Old Skool Gaming & Retro
    Replies: 6
    Last Post: 26th November 2002, 01:48 AM
  2. setting up a website
    By Danger Mouse in forum Web Hosting & Domain Names
    Replies: 7
    Last Post: 29th September 2002, 03:18 PM
  3. website problems
    By daveb47 in forum PC Problems
    Replies: 4
    Last Post: 10th September 2002, 10:31 AM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •