Announcement

Collapse
No announcement yet.

How to remove virus?

Collapse
X
 
  • Time
  • Show
Clear All
new posts

  • How to remove virus?

    Hello everyone,
    my site got virus. Please instruction me to remove this virus. I was running version 3.6.0 and just upgraded to 3.6.7 in this morning. my license was expired at the time 3.6.7 came out.



    Thank you
    Attached Files

  • #2
    It is not possible for the default vB scripts to have viruses. This is either from an add-on, something on your PC, or because you allow HTML in posts or sigs.
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment


    • #3
      I have a similar problem as the thread below


      a virus warning when user entering to my domain name ( The virus resides in the Temporary Internet files , with extension s2[1].htm ) but it'll be fine when people go to my website by domain_name/forums . it sounds to me like my domain infected the virus. is it possible the domain infected virus? i contacted my domain provider and they couldn't solve the problem.

      the virus/spyware try to redirect to search.ringtones.com or something like that. i don't remember exact name.

      I've read a lot of threads in here that people reported the iFrame virus attacked there websites.

      my forums deosn't allowed any kind of html. i have some add-on for audio streaming for years but we just found the virus recently so i believe the virus is not coming from those ad-on

      i really want to remove this virus from the from. please give me some advices

      Thanks

      Comment


      • #4
        Their host account got exploited, or their outdated vBulletin, or an insecure unofficial addon.

        Comment


        • #5
          Originally posted by Floris
          Their host account got exploited, or their outdated vBulletin, or an insecure unofficial addon.
          what's your suggestion?

          Comment


          • #6
            Back up everything.

            Get a daily host backup restored.

            Upgrade to 3.7.3 PL1

            Run diagnostics to find non-vb files.

            Revert templates and disable the hook system and uninstall unofficual plugins.

            Comment


            • #7
              Originally posted by Floris
              Back up everything.

              Get a daily host backup restored.

              Upgrade to 3.7.3 PL1

              Run diagnostics to find non-vb files.

              Revert templates and disable the hook system and uninstall unofficual plugins.
              I did and didn't see any non-vb files. i also upgraded to 3.7.3l1

              i contact the webhosting they said they can't help
              I'm sorry to hear that you are having problems. Because you are
              responsible for the contents of your account we can not scan your files
              for you. We recommend that you delete or overwrite any unknown files from
              your account. The fastest way is to simply re-upload all your known good
              files. If you do not have a local backup you can restore your files using
              one of the backups we make. This page explains how:

              Comment


              • #8
                Interesting how a host takes that policy, and does not seem to matter that scripts are running that compromises that account and the risk of getting deeper into the system.

                This also means that since they dont' scan the account you could probably build a warez ring and nobody would bother. I doubt that is the case and they suddenly police the content in a second ..

                Anyway.

                Check the products and the plugins, anything there you do not recognize? Check the content.

                Go to the vboptions > hooks > active? NO

                To turn it off. Additionally, to config.php add: efine('DISABLE_HOOKS', true);
                below <?php

                Then go check the plugins and the styles.

                Find any customized templates and see if any code you didn't add to it appears.

                Also go to the directory of the host, the main one, the publichtml one, the sub dirs,
                and scan it for unknown files, try to identify them.

                do ls -all, to display all hidden files too (or set ftp to display hidden files).

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...
                X
                😀
                🥰
                🤢
                😎
                😡
                👍
                👎