Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 11:33:53 AM

Pages: [1]   Go Down
  Print  
Author Topic: gumblar mailware  (Read 815 times)
Nassim Wassouf
Newbie
*
Offline Offline

Posts: 4


« on: May 06, 2009, 09:57:45 AM »

Hi
an alert apeer when I open any page in my foruem
I use Kasparsky in my pc
the message photo is here:

what to do?
plz help me
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #1 on: May 06, 2009, 10:40:31 AM »

Searching for just that domain on Google turns up a lot or results about it being related to a trojan it seems.  I would recommend following the steps provided here:

http://wiki.lunarpages.com/Web_Site_Security_Breaches

Do you have backups?  If so you might be able to roll back to a version without the exploit in place, or you might discuss your restore options with our support team at support@lunarpages.com.
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Nassim Wassouf
Newbie
*
Offline Offline

Posts: 4


« Reply #2 on: May 06, 2009, 11:34:40 AM »

is there any way to remoove this virus without loosing any post in my forume??

thanks for ur response

Nassim

Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #3 on: May 06, 2009, 11:44:34 AM »

Well, would depend on how bad it was, and when you were infected.  I would check on the backup status first, to see if you have a backup that would be before this got started.  What type of forum software do you use, and are you using the latest version?
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Nassim Wassouf
Newbie
*
Offline Offline

Posts: 4


« Reply #4 on: May 06, 2009, 05:31:04 PM »

Hi Sir

now I use vBulletin 3.8.2

I began to use it 2 days ago. but I didnt backed it up.

before, I was using vBulletin 3.6, I had got a full back up before Updating to vBulletin 3.8.2
the forum was cleaned before updating
after I update to vBulletin 3.8.2 I think that the new forum kept cleaned more than 12 hours ( I'm not sure )
everything go good until now on my new forum, only that massage appears.
I have kasparsky  (KIS8) on my PC; is it useful to remove the virus from my database?
wher this virus come from?
Please help me & remove the virus if possible
Sorry for my bad English
Nassim


« Last Edit: May 06, 2009, 05:39:34 PM by Nassim Wassouf » Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #5 on: May 07, 2009, 06:44:21 AM »

If you can, try to delete the code from your forums.  Next, you might want to run a full security scan on your own PC to make sure you are not infected yourself.  Your site might be also infected because your local PC have some virus which can grab stored passwords from your FTP client software and to do login to your sites saved there and upload there viruses.

Also, looks like you are now using the latest version of vBulletin 3.8.2, which is good.  You'll also want to update your account passwords once you are sure your PC is clean or from a PC that is not infected.  Once again, I would recommend checking out this post (http://wiki.lunarpages.com/Web_Site_Security_Breaches)

Your PC anti-virus program can only scan for things on your computer, and not on the server side.  Here's another good site I found that relates to this issue:

http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Nassim Wassouf
Newbie
*
Offline Offline

Posts: 4


« Reply #6 on: May 07, 2009, 08:11:41 AM »

Hi
I afrade I dont understand what code u ment to delet and from wher exactly.

about my PC I'm sure it's cleaned.

I knew also wher this virus com from. It came from other derty PC.

any way,

I'll try to update forum filse, do u think that it well be useful?

thaks a lot sir

I'll get back


Best regards
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #7 on: May 07, 2009, 08:30:26 AM »

You will need to find the locations where the code causing this warning comes from, and remove it.  Might try right-clicking on one of your pages, and select "view page source".  Then start looking for anything that might be out of the ordinary. 
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: