February 13, 2012, 01:57:33 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  

Advanced XP Defender


AddThis Social Bookmark Button AddThis Feed Button
Pages: [1]
  Print  
Author Topic: Advanced XP Defender  (Read 2036 times)
maresca
Newbie
*
Posts: 2


View Profile
« on: June 19, 2008, 12:50:07 AM »

Hi there

i am hoping someone might be able to help me here. About 2 weeks ago, our website was infected by a pop-up from the website, advancedxpdefender.com. It appears to be installing code on pages from our site (which is all in.asp coding) and uses a pop that states the user has 'not complete the scan'.

We have limited time and resources, and so far have managed to remove the code from the index page when its added. I am still not sure how they are accessing the site and managing to do this on a regular basis. we've moved hosts and they've still managed to attack the site. I don't know how these things work, whether its automated, or someone is 'manually' hacking the site.

I've made attempts to track down who this company is but to no avail. I'd love it if someone could give us some help on how to stop this once and for all.

Thanks
Logged
Bobby
Administrator
Newbie
*****
Posts: 290



View Profile
« Reply #1 on: June 25, 2008, 12:02:57 AM »

hello there,
the advancedxpdefender infection might be on the computer that hosts your website. if i needed to place a bet, i'd say the host computer is infected, but there's also several other possibilities.
you say you've removed the malicious code from index page, but it might be also inserted anywhere else in the website code. you should look through the code really carefully; i know it might take a lot of time, but it's worth it.
there's also a possibility that the infection is on the computers that are used to develop the website. in this case, everytime someone opens website code from the infected computer, advancedxpdefender sneaks into websites code. either developers computer or host computer is infected, the infection might reach the machine through network connections, so ALL the computer in the network may need to be scanned for parasites.
have you changed the passwords for accessing websites code after the infection appeared? if the attackers have your passwords, they can access the code remotely and do whatever they want.
you can search for malicious files using advancedxpdefender removal tutorial, you can also scan computer with free antispyware software. if the host computer belongs to third party company, you should strongly recommend them to take this issue seriously.
hope this helps and i hope to hear from you soon.
Logged

I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
maresca
Newbie
*
Posts: 2


View Profile
« Reply #2 on: June 25, 2008, 02:31:15 AM »

Quote from: "Bobby"
hello there,
the advancedxpdefender infection might be on the computer that hosts your website. if i needed to place a bet, i'd say the host computer is infected, but there's also several other possibilities.
you say you've removed the malicious code from index page, but it might be also inserted anywhere else in the website code. you should look through the code really carefully; i know it might take a lot of time, but it's worth it.
there's also a possibility that the infection is on the computers that are used to develop the website. in this case, everytime someone opens website code from the infected computer, advancedxpdefender sneaks into websites code. either developers computer or host computer is infected, the infection might reach the machine through network connections, so ALL the computer in the network may need to be scanned for parasites.
have you changed the passwords for accessing websites code after the infection appeared? if the attackers have your passwords, they can access the code remotely and do whatever they want.
you can search for malicious files using advancedxpdefender removal tutorial, you can also scan computer with free antispyware software. if the host computer belongs to third party company, you should strongly recommend them to take this issue seriously.
hope this helps and i hope to hear from you soon.



Many thanks Bobby - Lots of valuable feedback there. I'll make a point of acting on all you said there.

Cheers buddy, have a good one  :wink:
Logged
Bobby
Administrator
Newbie
*****
Posts: 290



View Profile
« Reply #3 on: June 25, 2008, 11:08:29 PM »

please don't hesitate to ask for further insistence  :wink:
Logged

I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
Pages: [1]
  Print  
 
Jump to:  




Recommended software:
STOPzilla
(90/100)
STOPzilla is a powerful anti-spyware program that detects, blocks, and removes malicious software allowing users to surf the Web not worrying about spyware, Trojan horses,...
Malwarebytes Anti Malware
(88/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t...
Spyware Doctor
(87/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and...
SpyHunter
(86/100)
SpyHunter is a quite simple, but yet highly effective spyware remover with an easy-to-use interface. This program is an excellent choice for users, who are...
XoftSpySE Anti Spyware
(84/100)
XoftSpySE, an anti-spyware program made by ParetoLogic, Inc., is a simple, but effective on-demand scanner with the typical set of functions but very easy to...
Encyclopedia of parasites:

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other