all our sites at Jodo Host hacked with malwareq

well we can help with FTP logs on both sides, http logs are more another issue really, we cannot commit the time requires to research personally every such issue on http logs.

esp when multi domain accounts as it makes the issue magnitudes harder each one.

Pretty much all my sites with a CMS are getting hacked. I think it is throught permissions settings. Weird that sites that have been around 5 years now suddenly get hacked.

actually they are most common, as they contain certain strings in the code that are visible then google can be used to search for just that, and they come back with a list of vulnerable sites. :frowning:

Actually, I think this is a bigger problem. Now I have sites that have no applications whatsover, no write permissions, plain old HTML sites that are affected. Client sites on other hosts do not.

And they are site on different accounts, different FTPs, and not Adobe affiliations.

I take that back. They all seem to be under the same FTP, which I have changed.

When I download the files to clean them up it says Access Denied when I try to open them. But all the permissions are correct.

Access denied on your local machine, or when trying to reupload to server? If local machine maybe need to give yourself owner/read/write/modify on the files?

Local machine. All the files are set with the correct permissions, but the folder is Read-Only and it won’t let me change it.

Note: it’s only the infected .html files that I cannot open.

Disregard the read-only on the folder. This is correct per Windows. But all owner/permission are correct and I cannot open the file with anything. I cannot even view the html file in a browser.

that is very odd, you have an AV that may be locking them due to iframe being detected maybe?

you should be able to right click file, go to properties, security, advanced. then go to ‘owner’ and click edit, add your login name as owner of the file, which will give you ultimate permissions on the file to do whatever, unless of course it is AV locking it.

I’m suspecting my AV as well. Unfortunately AVG does not allow you to just turn it off, so I have to uninstall it.

Yep that was it.

don’t open it in your browser :wink:

notepad is fine it can’t do any damages from there, and you can cleanup.

Once you find the code you can use the mreplace I mentioned:
http://www.medcalcsoftware.com/legacysoftware/mreplace/index.php

Yeah I am using a find/replace and it is working well. So is changing my FTP password all I can do? How do I prevent this from happening?

well, find the source of the issue, if it is FTP, somehow someone is getting the FTP password, and that is not from the server side, run MalwareBytes, run Ms Security Essentials or another AV, run Javacoolsoft Spyware blaster. Be leery of other AV/anti spam apps, there are several really good on the market, but download it from a trusted source (majorgeeks.com has most of these hosted)

btw I don t exactly mean on your PC, but the PC that is used most of the time. Also if any network connected PCs they can invade as well, so they need to be scanned if in same network as infected pc.

From there, once you have them cleaned we can set the FTP to read only for a few days(request in ticket) and this will prevent any changes and also allow a close inspection of logging denials for how many FTP attempts are being made to the account as well.