Reply
How to remove Antivirus 2009 infection from website
Old 01-17-2009, 04:03 PM Unhappy How to remove Antivirus 2009 infection from website
Junior Talker

Posts: 3
Trades: 0
Hi guys,

I'm reaching the end of my tether with Antivirus 2009. A friend has a website, www.visi.es, which has become infected with this poisonous piece of software.

Does anyone have any experience rooting out the infection and killing it? I've read a million guides, and followed most of them, but it seems they are all for individual computers, not websites. I've had a good look through, and I can't see anything immediately suspiscious...

The strange thing is that when you access it, only sometimes does it redirect to their website. I don't know. Whatever it is, any help at all would be very much appreciated.

Rob
generalche is offline
Reply With Quote
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 01-17-2009, 04:08 PM Re: How to remove Antivirus 2009 infection from website
Decaf's Avatar
Ultra Talker

Posts: 490
Name: Adam
Trades: 0
Completely delete your files and upload from the latest backup, then apologize to your loyal viewers. (This is the easiest way, but not the best.)
__________________
Decaf is offline
Reply With Quote
View Public Profile Visit Decaf's homepage!
 
Old 01-17-2009, 06:19 PM Re: How to remove Antivirus 2009 infection from website
chrishirst's Avatar
Super Moderator

Posts: 22,225
Location: Blackpool. UK
Trades: 0
Antivirus 2009 is spyware that infects YOUR machine it will NOT be on the server.

It is NOT a virus.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | People Counting System | Bits & Bobs
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 01-17-2009, 06:27 PM Re: How to remove Antivirus 2009 infection from website
Decaf's Avatar
Ultra Talker

Posts: 490
Name: Adam
Trades: 0
(what i meant was) If the server has been infected with the virus then you need to fix that.
__________________
Decaf is offline
Reply With Quote
View Public Profile Visit Decaf's homepage!
 
Old 01-17-2009, 06:27 PM Re: How to remove Antivirus 2009 infection from website
Brian07002's Avatar
Defies a Status

Posts: 1,589
Name: ...
Location: ...
Trades: 0
Restore your servers machine if you have a backup, otherwise, go with either Mcafee or Norton if your on a windows based machine. I don't know what to tell ya, other than don't run ANY programs that you don't know about. You can always get a hand written note from the software company.
__________________
Sig Less - Have some site you want me to put here? Will put here for a couple of paypal bucks.
Brian07002 is online now
Reply With Quote
View Public Profile
 
Old 01-17-2009, 07:32 PM Re: How to remove Antivirus 2009 infection from website
Junior Talker

Posts: 3
Trades: 0
Thanks for the replies - I don't know how it happened, but it seems Antivirus 2009 has hijacked the web page... could it be a problem with the host? Their server has the infection?

Yeah, about those backups... heh... funny story... the friend whose site it is really isn't a webmaster, and not really having much of a clue about these things, didn't see the point in making backups.

Sucks, I know. It does mean that the only thing we have to work with is the files on the site at the moment...

Appreciate the input guys .
generalche is offline
Reply With Quote
View Public Profile
 
Old 01-17-2009, 08:01 PM Re: How to remove Antivirus 2009 infection from website
Brian07002's Avatar
Defies a Status

Posts: 1,589
Name: ...
Location: ...
Trades: 0
Quote:
Originally Posted by generalche View Post
Thanks for the replies - I don't know how it happened, but it seems Antivirus 2009 has hijacked the web page... could it be a problem with the host? Their server has the infection?

Yeah, about those backups... heh... funny story... the friend whose site it is really isn't a webmaster, and not really having much of a clue about these things, didn't see the point in making backups.

Sucks, I know. It does mean that the only thing we have to work with is the files on the site at the moment...

Appreciate the input guys .
The first thing I would do is do a search for all of the files that are important to your site:

1. Html pages
2. Images / Videos / Sounds
3. Scripts php, javascript, etc.

Then copy those files onto a removal hard drive or another non-infected pc, then format the infected machine, then re-install from scratch. That would be my first choice in this case.

If you don't want to format, then I would try an online virus scanner to remove the culprit, but that usually doesn't work unless you buy it. It will however, tell you what is infecting your pc, but it won't remove it until you buy it.

Good Luck.
__________________
Sig Less - Have some site you want me to put here? Will put here for a couple of paypal bucks.
Brian07002 is online now
Reply With Quote
View Public Profile
 
Old 01-18-2009, 04:19 AM Re: How to remove Antivirus 2009 infection from website
Skilled Talker

Posts: 60
Name: Michael Swan
Location: United Kingdom
Trades: 0
As stated above. The member believes that the Hosting Company is infected.

This would be the issue I believe, but looking through your HTML code and files for abnormal code that you did not put there.

It may be partly the host, and then some kind of Script or Code injection that is being malicious.

~ Mike
ms2134 is offline
Reply With Quote
View Public Profile Visit ms2134's homepage!
 
Old 01-18-2009, 07:18 AM Re: How to remove Antivirus 2009 infection from website
chrishirst's Avatar
Super Moderator

Posts: 22,225
Location: Blackpool. UK
Trades: 0
There is NOTHING on that site that brings up a warning for me. Tried with several different configurations of protection all the way up to "Paranoid".

"Antivirus 2009" is very very unlikely to be on the server unless somebody has been browsing the Internet while being actually ON the server and allowed the malware to be installed. And given that it is a *nix box and the vast majority of spyware can only "hook" in to a Windows OS, that is highly unlikely.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | People Counting System | Bits & Bobs
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 01-19-2009, 11:24 AM Smile Re: How to remove Antivirus 2009 infection from website
Junior Talker

Posts: 3
Trades: 0
Thanks everyone for your suggestions and help.

In the end, after having run about a million different scans and finding precisely nothing, we contacted the support from the hosting company.

They had a look, and found that the .htaccess file had some lines of code that were redirecting users depending on the referrer. E.g. if you accessed the site from a google or yahoo search, it redirected you to Antivirus 2009 spam sites.

The reason we didn't see it was that the was no .htaccess file, only a "ht" file, and a php file which renamed ht to .htaccess when it was accessed.

Anyway, all cleaned, deleted and pristine once again now. And several back ups made too. Lesson well learned.

Thanks again!

Rob
generalche is offline
Reply With Quote
View Public Profile
 
Old 01-19-2009, 12:06 PM Re: How to remove Antivirus 2009 infection from website
King Spam Talker

Posts: 1,409
Trades: 0
Nice follow up now stick around and visit with us.
__________________
Colbyt
colbyt is online now
Reply With Quote
View Public Profile
 
Old 01-19-2009, 12:55 PM Re: How to remove Antivirus 2009 infection from website
chrishirst's Avatar
Super Moderator

Posts: 22,225
Location: Blackpool. UK
Trades: 0
One thing you do need to find out is how the files got there
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | People Counting System | Bits & Bobs
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 01-19-2009, 01:01 PM Re: How to remove Antivirus 2009 infection from website
rolda hayes's Avatar
Webmaster Talker

Posts: 650
Name: Darren
Location: England
Trades: 0
Exactly... That sounds pretty scary when someone can change your htaccess file?

You also need to ask the hosting company what they are going to do to stop it happening again... Glad you got it sorted though
__________________
"I always wanted the adoration of John Lennon - With The Anonimity of Ringo Starr..."
QuizBay Help with the testing of this Beta site!
rolda hayes is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to How to remove Antivirus 2009 infection from website
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 



Page generated in 0.17200 seconds with 13 queries