Help! Why Do My Sites Show Dangerous Downloads Warnings?

16 replies
I have some WordPress blog sites that I have been developing for many months without any problems. However, almost a month ago, people started relating to me when they try to go to my sites, they now display a "Dangerous Downloads" warning.

I have eliminated plugins, links, and all other attributes which each of the sites had in common, but to no avail. The sites are still showing a dangerous downloads warning as of 8/2/2012.

Has anyone else had this problem? What are the possible causes and solutions?

I even changed the themes of the affected sites to a theme I use on one of my sites which do not show the alerts.

I would sure appreciate help and assistance from fellow Warriors in resolving this issue.

Thanking you much in advance.

Terry
#dangerous #downloads #show #sites #warnings
  • Profile picture of the author zapseo
    Don't have enough information here.

    Are you saying your sites are getting what we call "the red screen of death" -- which is the Google SafeBrowsing API announcing that your site is distributing malware?

    In that case, your website has been hacked.

    I've cleaned up hacked sites for several years now, but don't do that so much anymore.

    But if you would like assistance, pm me. (Or connect with me on skype -- letting me know HOW you know of me. I don't connect with people who just send a contact request and no further info.)

    Live JoyFully!

    Judy
    {{ DiscussionBoard.errors[6744398].message }}
    • Profile picture of the author MP80
      I agree.. we need more info.

      Are you using bit.ly as a URL shortener for any of the links to your site?

      If so, they will sometimes (often?) pop an ominous warning up, even when your site is clean.
      Signature
      Before you do ANYTHING else in your day - do at least ONE thing that brings money into your business.
      {{ DiscussionBoard.errors[6744430].message }}
    • Profile picture of the author tmdassc
      Judy,

      Google does not have problems with the sites and they come up clean when googled. I have only gotten the notifications myself when I type the site links into yahoo. I then get a warning from "SearchScan" beta.
      {{ DiscussionBoard.errors[6744486].message }}
      • Profile picture of the author MP80
        Yes, it has been hacked.. Norton says it is 'Exploit Kit Redirect'.

        This signature detect attempts to download exploits from a malicious toolkit which may compromise a computer through various vendor vulnerabilities.
        Signature
        Before you do ANYTHING else in your day - do at least ONE thing that brings money into your business.
        {{ DiscussionBoard.errors[6744634].message }}
        • Profile picture of the author tmdassc
          Originally Posted by MP80 View Post

          Yes, it has been hacked.. Norton says it is 'Exploit Kit Redirect'.
          Thanks MP80,

          I am in the index.php editor now and I am seeing what Nathan referred to. So that looks like that may be the problem. going to give that a try when Nathan replies back.

          I much appreciate your assistance to this point, and will be following suggestions.
          {{ DiscussionBoard.errors[6744792].message }}
  • Profile picture of the author Nathan Briggs
    You have got a hack in there, first off check your index.php files for some gobbledegook, probably at the start of the file beginning with eval(base64_decode( ). Removing that is step one, step two is to contact a professional (ahem) to do a thorough clean out & hardening job.

    This particular hack is actually pretty clever, it tries to avoid triggering a blacklisting by only appearing sometimes, probably also avoiding Chrome browsers and maybe Firefox. That's why you can't see it, and why you aren't blacklisted yet.
    Signature

    I clean up and secure hacked WordPress sites. PM me to get started.

    {{ DiscussionBoard.errors[6744603].message }}
    • Profile picture of the author tmdassc
      Originally Posted by Nathan Briggs View Post

      You have got a hack in there, first off check your index.php files for some gobbledegook, probably at the start of the file beginning with eval(base64_decode( ). Removing that is step one, step two is to contact a professional (ahem) to do a thorough clean out & hardening job.

      This particular hack is actually pretty clever, it tries to avoid triggering a blacklisting by only appearing sometimes, probably also avoiding Chrome browsers and maybe Firefox. That's why you can't see it, and why you aren't blacklisted yet.
      Howdy Nathan,

      Thanks much for your reply. Note, I have changed the theme on the sites, so they are not the same files as they were when his first started.

      However, I will, as a precaution and process of elimination - check the index.php files as you have suggested.

      Thanks,

      Terry
      {{ DiscussionBoard.errors[6744653].message }}
    • Profile picture of the author tmdassc
      Originally Posted by Nathan Briggs View Post

      You have got a hack in there, first off check your index.php files for some gobbledegook, probably at the start of the file beginning with eval(base64_decode( ). Removing that is step one, step two is to contact a professional (ahem) to do a thorough clean out & hardening job.

      This particular hack is actually pretty clever, it tries to avoid triggering a blacklisting by only appearing sometimes, probably also avoiding Chrome browsers and maybe Firefox. That's why you can't see it, and why you aren't blacklisted yet.
      Nathan,

      I just checked and saw what you were referring to. How much of that do I remove? What should be at the beginning of the index.php? I don't want to remove too much and render the site non-functional.
      {{ DiscussionBoard.errors[6744765].message }}
  • Profile picture of the author faisalmaximus
    tmdassc, the possible reason and solutions are :
    1. The hosting service you are using may be affected by malicious objects, change the hosting, hope it will work.
    2. The problem may be due to domain name registrar, if the first option doesn't work, please change your domain registrar.
    3. Download all your files from public_html and scan through antivirus software, if get any malicious object or virus, remove it and upload the files again.
    Please try these, hope your site will be ok.

    Thank you
    Faisal
    {{ DiscussionBoard.errors[6744654].message }}
    • Profile picture of the author tmdassc
      Originally Posted by faisalmaximus View Post

      tmdassc, the possible reason and solutions are :
      1. The hosting service you are using may be affected by malicious objects, change the hosting, hope it will work.
      2. The problem may be due to domain name registrar, if the first option doesn't work, please change your domain registrar.
      3. Download all your files from public_html and scan through antivirus software, if get any malicious object or virus, remove it and upload the files again.
      Please try these, hope your site will be ok.

      Thank you
      Faisal
      Thanks Faisal,

      All the domain name are the same for all of my sites, but not all are affeced. The same goes for hosting. However, I will be checking into your suggestions if all else fails.

      Many thanks.

      Terry
      {{ DiscussionBoard.errors[6744811].message }}
    • Profile picture of the author zapseo
      Originally Posted by faisalmaximus View Post

      tmdassc, the possible reason and solutions are :
      1. The hosting service you are using may be affected by malicious objects, change the hosting, hope it will work.
      2. The problem may be due to domain name registrar, if the first option doesn't work, please change your domain registrar.
      3. Download all your files from public_html and scan through antivirus software, if get any malicious object or virus, remove it and upload the files again.
      Please try these, hope your site will be ok.

      Thank you
      Faisal
      Say what ????

      About the only thing that makes ANY kind of sense in those suggestions is #3.

      @tmdassc (ah, just found your name ... Terry!)

      Just wanted to let you know that I had to step away, and Nathan is my business partner in things having to do with website security and wordpress, so I gave him a head's up about your thread here.

      I asked him to come over and help you out.

      In general, if your index.php file is infected (with the code that Nathan told you about) -- chances are other php files on your hosting account are infected as well.

      Especially if you have add-on domains.

      There are web security people who have said that they've never seen a hacked site where there wasn't a backdoor installed. While I can't say that I've always found backdoors ... I have found backdoors in many -- and often, the backdoors were installed months, and sometimes even years ago.

      I've even found backdoors on client accounts that had been sitting there for years.

      Because there is a number of ways that backdoors & hacks can be obfuscated, though (and they get trickier all the time), it's difficult to find them all.

      Incidentally, you mentioned that you changed the theme...it's not just the theme ... it's the whole WordPress install that would need to be changed out. The "index.php" file of mention is not part of theme files, but of the WordPress install itself.

      Hope that helps!

      Live JoyFully!

      Judy
      {{ DiscussionBoard.errors[6745132].message }}
  • Profile picture of the author Nathan Briggs
    Replied by PM. Basic: remove eval and everything in the brackets that follow it.
    Signature

    I clean up and secure hacked WordPress sites. PM me to get started.

    {{ DiscussionBoard.errors[6745003].message }}
    • Profile picture of the author tmdassc
      Originally Posted by Nathan Briggs View Post

      Replied by PM. Basic: remove eval and everything in the brackets that follow it.
      Many Thanks Nathan,

      I have PMed you and related everything to you. I have cleared all that coding out and will be following the other steps you gave me.

      Thank you so much as you have been very helpful. I know now to only trust wordpress.org for installs.

      A big ole Texas Thankya to you.

      Terry
      {{ DiscussionBoard.errors[6745041].message }}
  • Profile picture of the author Nathan Briggs
    To be clear, what I said was to grab a copy of the WP code from wordpress.org and use that to overwrite all the WP files on your hosting. It won't, as Judy said, remove any backdoors that have been added, but it is an easy procedure that will help until you can get a pro to look over it (to be safer, delete wp-*.php - except wp-config.org and all in wp-includes and wp-admin; also remove and reinstall from zip all plugins and themes, then update everything -and keep it updated; this is a harder procedure, so be careful).
    Signature

    I clean up and secure hacked WordPress sites. PM me to get started.

    {{ DiscussionBoard.errors[6745193].message }}
  • Profile picture of the author jtprattmedia
    definitely sounds like a hacked website. You have to get to the root cause, even if you remove the infected code it'll happen again if you don't plugin the whole. Check out this page for detailed fix info: How to Fix a Hacked Wordpress Blog | JTPRATT Wordpress Consultant
    {{ DiscussionBoard.errors[6801789].message }}

Trending Topics