Announcement

Collapse
No announcement yet.

Google marked me as Bad site, cant find malware, please help

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    When I got the same on my site it gave me a specific thread url. With yours it's saying the whole site. I didn't use google webmaster tools to check it but that's worth signing up for.

    I wonder who your advertisers are (apart from adsense) - sometimes that's a way in for malware.

    Comment


    • #17
      If its ok, i dont have external links or hotlinks on my /forum.

      Maybe it was temporarily because it was in de sitebar when google went by? But this way there must be a thread or something else where.

      Comment


      • #18
        I feel your pain dammie. If it's any consolation have a read of this: http://searchengineland.com/google-g...-briefly-16387

        what about sigs? hotlinked images there?

        Comment


        • #19
          Is there a way to scan this??

          I downloaded all my files by ftp and searched for the URL or parts which Google told me but i found nothing.

          But something happened, after thay first marked /forum now they marked /photopost too

          Really dont know what to do .......... nice work between Christmas and Newyear, was affraid to be borred

          Comment


          • #20
            23rd of December i banned a "chinese" email for SPAM. I really cant recall what he did to me but i banned him. I fysically removed his content so i cant see it anymore. But some deeplink should be gone......

            Comment


            • #21
              Originally posted by dammie View Post
              But something happened, after thay first marked /forum now they marked /photopost too

              Really dont know what to do ...)
              Perhaps they found a security hole in your Photopost?
              Search for new files-folders by date on your whole site.


              vB5 is unequivocally the best forum software, but not yet...

              Comment


              • #22
                hmmm maybe.

                for the /forum i read this at google:
                Of the 35 pages we have in the past 90 days at the site tested, have 4 page (s) without user consent malicious software being downloaded and installed. The last time Google visited this site was on 28/12/2010. The last time suspicious content was found on this site was on 27/12/2010.

                Could it be gone at the /forum ?

                /photopost:
                Of the 2 pages we have in the past 90 days at the site tested, have 2 page (s) without user consent malicious software being downloaded and installed. The last time Google visited this site was on 28/12/2010. The last time suspicious content was found on this site was on 12/28/2010.

                I think you are right, i will update that too, at least it resets all the files

                Comment


                • #23
                  Originally posted by dammie View Post
                  I think you are right, i will update that too, at least it resets all the files
                  Look for suspicious folders, .php files in the whole public folder.
                  Such as ssc or yen folder with 9,000 files in it? What the hell is it???

                  In my case the cause of the infection could be "Gallery2". Gone.


                  vB5 is unequivocally the best forum software, but not yet...

                  Comment


                  • #24
                    ok, thx for your info, will look for that tomorrow.

                    I had Gallery2 before. Allthought i deleted most of it, there was still someting in htaccess which i cleaned up now. Hope this helps soon.

                    Comment


                    • #25
                      hmmmm Google went by and still found malware......im getting crazy

                      Isnt there any addon which could see what files are changed if they get compared with the originals?

                      Comment


                      • #26
                        Is it the site in your profile?
                        .......

                        Comment


                        • #27
                          Yes it is now.

                          For the first time i saw the malware when i visited the link from my profile.

                          Seems like it only happens when some is getting referred or something.

                          Comment


                          • #28
                            Originally posted by dammie View Post
                            For the first time i saw the malware when i visited the link from my profile.
                            That is a nasty one.I could get out only with Control-Alt-Delete


                            vB5 is unequivocally the best forum software, but not yet...

                            Comment


                            • #29
                              Normal?

                              In the source of my index (when not redirect) i see this under my copyright line:

                              PHP Code:
                              <div id="footer_morecopyright" class="shade footer_morecopyright">
                                  <!-- Do 
                              not remove cronimage or your scheduled tasks will cease to function -->
                                  <
                              img src="http://www.domain.nl/forum/cron.php?rand=1293694362" alt="" width="1" height="1" border="0" />
                                  <!-- Do 
                              not remove cronimage or your scheduled tasks will cease to function -->
                                  
                              </
                              div



                              Is this normal??

                              Comment


                              • #30
                                @ beishe: Sorry

                                Comment

                                Related Topics

                                Collapse

                                Working...
                                X