Author Topic: Falso postivio en web  (Read 2904 times)

0 Members and 1 Guest are viewing this topic.

segoviafoto

  • Guest
Falso postivio en web
« on: February 14, 2012, 06:05:58 PM »
Me comentan los usuarios de mi web -http://www.segoviafoto.es que existe un virus SOLO cuando tienen antivirus avast, he analizado el sitio de diversos modos Sucuri Sitecheck, etc y no da virus no troyano.

Por favor verifiquen la URL porque no encontramos virus ni troyanos y está impidiendo a la gente entrar en nuestra web.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Falso postivio en web
« Reply #1 on: February 14, 2012, 06:27:49 PM »
Puede usted seguir las instrucciones (en Inglés) de aqui ?

Quote
The vast majority of malware today is distributed over the web, mostly by means of hacked (otherwise legitimate) sites. The attacker usually injects malicious some scripts into some (or all) pages on the site, waiting for an unsuspecting user to visit the site and possible infect his/her machine.

And this is where avast’s detection capabilities really excel. Its abilities to detect these web-based malicious scripts are second to none, and thanks to the Web Shield and Script Blocking providers, they are used exactly when needed, doing an excellent job stopping the web-based malware right on the entry point.
The best things in life are free.

segoviafoto

  • Guest
Re: Falso postivio en web
« Reply #2 on: February 14, 2012, 06:32:02 PM »
si, y el código está limpio de amezanas es un wordpress estricto y no hay código inyectado...

gracias

spg SCOTT

  • Guest
Re: Falso postivio en web
« Reply #3 on: February 14, 2012, 06:34:02 PM »
Hi segoviafoto, welcome to the forum :)

Sorry, I don't speak spanish, so someone will have to translate for me ;)

Unfortunately it appears that the site is infact infected.

There is a script that points to a site that is blocked by avast. This script has been seen many times recently on the forum, and appears to be related to theming.

One method of attempting to solve it is to use Exploit Scanner by Wordpress:
This is from a thread which had the same type of script embedded in the pages.
(http://forum.avast.com/index.php?topic=92742.0)

Polonus had a link to a scanner that helped identify the issue, it may be of some help to you:

...

I found the problem. It was old timthumb.php file!!!

Exploit Scanner show me all of infected files and now everything is ok with my website...

Well the sucuri alert is not for an outdated  WordPress version, the alerts is foir that specific theme: wordpress London live theme

Use the Wordpress exploit scanner: http://wordpress.org/extend/plugins/exploit-scanner/
This plugin is far from perfect, so you might have to plough through the code for changes yourself,
You fell victim to a php hack so you have to secure the use of that first,

polonus

Scott

iroc9555

  • Guest
Re: Falso postivio en web
« Reply #4 on: February 14, 2012, 10:05:21 PM »
@ Scott

Thanks for dropping by.

@ segoviafoto

¿ Puedes entender lo que spg SCOTT te explico ?

Hay un script que te redirije a un sitio que Avast! bloquea. Este script se ha visto recientemente muchas veces en el foro. Parece que es relacionado con theming. Un metodo para atentar resolverlo es con el uso de Exploit Scanner de Wordpress

Despues te da el enlace a un problema parecido.

 BTW Ya Virus Total detecta tu sitio con Bit defender.

https://www.virustotal.com/url/19ce09abe0b8cedfee75511d321523cad2ae20516250041c58a7254f7454169f/analysis/1329251426/

y aunque Sucuri todavia no detecta nada urlQuery detecta algo sospechoso.

http://urlquery.net/report.php?id=21525

Si necesitas mas informacion puedes pedir ayuda en el foro de Viruses and worms donde Polonus o Pondus pueden que investiguen mas profundamente y darte mas datos.

Suerte.
« Last Edit: February 14, 2012, 10:09:25 PM by iroc9555 »