Author Topic: Help! Virus on my webpage: How to remove?  (Read 2507 times)

0 Members and 1 Guest are viewing this topic.

Offline apeka

  • Jr. Member
  • **
  • Posts: 32
Help! Virus on my webpage: How to remove?
« on: October 05, 2011, 07:55:27 PM »
Hello,

avast1 Free just detected a trojan horse called JS:Redirector-KG when accessing my homepage. Of course avast! blocked this site as well...
How do I get rid of this? I don't know... Please help.
Thanks in advance...

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Help! Virus on my webpage: How to remove?
« Reply #1 on: October 05, 2011, 08:22:04 PM »
Rather depends on A) what that home page URL is and B) who the webmaster is if it is infected.

A. When posting the URL change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites, thanks. Then it can be investigated.

B. If you aren't the webmaster and it is infected, there is little you can do other than report it to the webmaster, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline apeka

  • Jr. Member
  • **
  • Posts: 32
Re: Help! Virus on my webpage: How to remove?
« Reply #2 on: October 05, 2011, 08:38:25 PM »
Hello,

I'm the webmaster of this site and the url is: wXw.kamphuis-serpa.nl. Hope this is enough information right now.. I also e-mailed the guy who built the site for me, as well as my hosting provider. I just discovered I also can't login to the CMS anymore. It seems to be replaced or something.. It seems that somebody or something made quite a mess of my site...

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Help! Virus on my webpage: How to remove?
« Reply #3 on: October 05, 2011, 09:00:22 PM »
There appears to be a compressed {gzip} loaded with the index page, this is what avast is alerting on, image1. I don't know if you are aware of that or it is legit, but the contents appear obfuscated and I don't know if that is what is throwing avast, image2.

Another site http://sitecheck.sucuri.net/scanner/ also confirms this detection so it would appear that your site has been hacked. Visit this site and enter your URL and you will see the areas that need looking at. See image3 of an extract of just one of the issues.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security