xejay Posted May 9, 2011 Share Posted May 9, 2011 Hello,I have made alot of shops on prestashop, and now i geting malware report from google.I found this line in index.php file. How avoid this one? Link to comment Share on other sites More sharing options...
Captain FLAM Posted May 9, 2011 Share Posted May 9, 2011 I'm building a web server that will be secure against this f... hackers.If you're interested to take a place on it, you can Call me :On Skype (see my signature) or by PM. Link to comment Share on other sites More sharing options...
xejay Posted May 9, 2011 Author Share Posted May 9, 2011 Sorry i dont need other hosting provider, i need fix that problem... Link to comment Share on other sites More sharing options...
rakepl Posted May 10, 2011 Share Posted May 10, 2011 I got it today too. Somebody, please help ! Link to comment Share on other sites More sharing options...
ruilong Posted May 10, 2011 Share Posted May 10, 2011 This should help locate the files.Upload it in the root folder and point your webbrowser to it, it will give you a list of all files infected, either "remove the malware code" or replace with original files.for imgbbb code, you may will need to change the code in the file to search for bbb version instead.And change your FTP passwords!! that's most likely how they got access to your hosting provider. fixgumblar.php Link to comment Share on other sites More sharing options...
rakepl Posted May 10, 2011 Share Posted May 10, 2011 Hi Ruilong !Very nice script. Today I had to handly edit all effected index.php file. Now I use your script scanning my site and I found 2 strange file. clearance.php in root folder and goal.php in admin folder and .//img/scenes/thumbs/index.php INFECTED!.//mails/en/index.php INFECTED!.//mails/es/index.php INFECTED!.//mails/fr/index.php INFECTED!.//modules/blockuseronline/index.php INFECTED!.//fixgumblar.php INFECTED!. Where and how "they" can edit and write to all index.php files, and maybe only index.php in first or second level in PS ?My [spam-filter] ask me how our site got infected ? In my ftp site, I found a folder ".log/name of mysite" in root folder with a hundred strange html. html2 html3, to html7 that I attach here, what are they and what for ?Thank you.267.05.2011I removed the attchment beacause it link to my site !!!! Link to comment Share on other sites More sharing options...
ruilong Posted May 11, 2011 Share Posted May 11, 2011 Gumblar virus/trojan/malware is usually a sign that they have access to your FTP.so if you detect these changes on your server, CHANGE THE FTP PASSWORD!Also, scan your local computer for any malware, as it's usually some kind of hack/infection on your local PC that picks up the passwords from your FTP software, like Filezilla for instance. Atleast this is what I found out about this little bugger when googling on it.The attack on your system is two steps,1. They infect your index.php and index.html with the image file, this notifices the people behind this virus that they have access to your site.2. They modify your .htaccess file, upload a bunch of crap that seems to be used for SEO boosting their own sites. 3. who knows.. Link to comment Share on other sites More sharing options...
rakepl Posted May 12, 2011 Share Posted May 12, 2011 Thank you for your reply.I just changed ftp password but my google index is potential decrease from 7200 to 2820 or sometime get 4000 something. How can I repair it ?I asked about folder .log in root folder and admin folder contain with hundred strange files. Will I leave them or remove from my server ? What are they ?Thank you.Rakepl Link to comment Share on other sites More sharing options...
ruilong Posted May 12, 2011 Share Posted May 12, 2011 Probobly the "hackers" files for seo pumping their sites.If you didn't put it there, delete it. Link to comment Share on other sites More sharing options...
rakepl Posted May 12, 2011 Share Posted May 12, 2011 Thank you.I just deleted them Link to comment Share on other sites More sharing options...
calvincover Posted January 9, 2013 Share Posted January 9, 2013 how do I fix this? Warning: fread() [function.fread]: Length parameter must be greater than 0 in /homepages/21/d3******/htdocs/file-name***/Store 1.5.3.0/prestashop/fixgumblar.php on line 18 .//fixgumblar.php INFECTED! Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now