Google found malicious software on my site…. Now what?
-
I received this email from Google:
Dear site owner or webmaster of solarbus.org,
We recently discovered that some of your pages can cause users to be infected with malicious software. We have begun showing a warning page to users who visit these pages by clicking a search result on Google.com.
Below are some example URLs on your site which can cause users to be infected (space inserted to prevent accidental clicking in case your mail client auto-links URLs):
https://www.solarbus .org/
https://www.solarbus .org/solar.shtmlHere is a link to a sample warning page:
https://www.google.com/interstitial?url=http%3A//www.solarbus.org/We strongly encourage you to investigate this immediately to protect your visitors. Although some sites intentionally distribute malicious software, in many cases the webmaster is unaware because:
1) the site was compromised
2) the site doesn’t monitor for malicious user-contributed content
3) the site displays content from an ad network that has a malicious advertiserIf your site was compromised, it’s important to not only remove the malicious (and usually hidden) content from your pages, but to also identify and fix the vulnerability. We suggest contacting your hosting provider if you are unsure of how to proceed. StopBadware also has a resource page for securing compromised sites:
https://www.stopbadware.org/home/securityOnce you’ve secured your site, you can request that the warning be removed by visiting
https://www.google.com/support/webmasters/bin/answer.py?answer=45432
and requesting a review. If your site is no longer harmful to users, we will remove the warning.Sincerely,
Google Search Quality TeamAll of my site is not just wordpress, so the problem is not necessarily wordpress… however I have only one script running on the site other than wordpress, and from what I’ve read, it’s the scripts that are vulnerable.
I only had one plugin installed on my wordpress blog and I just removed it in case that was the problem. I also upgraded to wordpress 3.0.
Now I am going to mirror my entire site to my local machine and then I would like to scan it for this “malware” that Google found.
Can anyone recommend a tool for scanning for malware? I’m guessing I need something different than a regular virus scanner.
I should add.. that recently I have found that the htaccess file in my site’s root directory (not the blog root directory) is being altered and this is causing my wordpress blog to malfunction. I don’t know if this is related.
Any help is appreciated. Thanks
- The topic ‘Google found malicious software on my site…. Now what?’ is closed to new replies.