Very, very strange malware. Please help me

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
scorcher
Joomla! Apprentice
Joomla! Apprentice
Posts: 13
Joined: Mon Nov 09, 2009 9:03 pm

Very, very strange malware. Please help me

Post by scorcher » Sun Jan 12, 2014 11:56 am

Hello
Sory for my grammar, but english insn't my native language. I'm from Poland.

I have very, very strange type of malware. This thing works only from links from google/facebook, only few times per hours/days. I haven't this alert (!), but my users told me that I have virus on site.

Now:
1. please go to google, type "sportowa zgora" and go to sportowa.zgora.pl (no direct, from google!)
or
2. go to: https://www.facebook.com/sportowazgorapl and click one of link to my site

You will have virus alert and redirect to adultfinder. Now the most interesting this. You will have this only once! If you try do this second, third... time, you will have clean site.

I don't know why. Maybe I'm not expert in security, but I tryied everything. EVERYTHING! Every tutorial from "site hack", download site and scan, clamscan nad maldet on my VPS. EVERYTHING and nothing found. I search eval, base64_decode, gzipdeflate... NOTHING

Please help me because I haven't any ideas
from Poland

User avatar
numinousmedia
Joomla! Ace
Joomla! Ace
Posts: 1567
Joined: Fri Dec 16, 2011 6:13 pm
Location: Barberton, OH
Contact:

Re: Very, very strange malware. Please help me

Post by numinousmedia » Tue Jan 14, 2014 4:06 am

It's been my experience that scanners like the ones you've tried will not always find infections. Just because these scanners don't report finding an infection, doesn't mean it isn't there. This sort of Google/Facebook redirection hack is pretty common, especially with Joomla 1.5 sites.

You need to follow the directions located here: http://forum.joomla.org/viewtopic.php?f=432&t=475313

It's time consuming and tedious, but the process does work.
Ryan
Frontend Developer and Joomla Professional
Ethode Website Development: http://www.ethode.com
Personal Site: http://www.numinousmedia.com

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 20652
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ Germany/ S'pore/Bogor/ North America
Contact:

Re: Very, very strange malware. Please help me

Post by leolam » Tue Jan 14, 2014 6:05 am

Visit myjoomla.com to make your life easier

Leo 8)
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -


Locked

Return to “Security in Joomla! 1.5”