Results 1 to 9 of 9
  1. #1
    worke is offline Private Member
    Join Date
    August 2018
    Posts
    27
    Thanks
    2
    Thanked 1 Time in 1 Post

    Default Possible malware - need help

    Hello,

    something really strange happened to my site. Any assistance will highly appreciated.

    I`m talking about the site roulettetrip . com

    When I visit the site on the top left corner it shows me a message If I want to allow/disallow notifications. After that when I click somewhere on the site it redirects me to some sh** pages. It is only on my site, so the problem is not because of my browsers.

    Any idea how to identify the source of this problem? I have not installed any additional plugins last 3-4 months, and Have no idea where this come from

  2. #2
    PromoteCasino is offline Private Member
    Join Date
    June 2013
    Location
    London
    Posts
    1,117
    Thanks
    1,074
    Thanked 496 Times in 335 Posts

    Default

    Have a look on this site https://sitecheck.sucuri.net it showed up as malware it may help in identifying the cause.

    But it is not nice. Best of luck
    BettingOffers.bet - Latest offers and bonuses from reputable UK bookmakers. A New project underway but a long way to go Bookie Rewards

  3. #3
    PromoteCasino is offline Private Member
    Join Date
    June 2013
    Location
    London
    Posts
    1,117
    Thanks
    1,074
    Thanked 496 Times in 335 Posts

    Default

    Just seen this plugin it may be able to help search for Anti-Malware Security and Brute-Force Firewall.
    BettingOffers.bet - Latest offers and bonuses from reputable UK bookmakers. A New project underway but a long way to go Bookie Rewards

  4. #4
    Nenad is offline Public Member
    Join Date
    June 2019
    Posts
    546
    Thanks
    311
    Thanked 155 Times in 128 Posts

    Default

    Hi,

    I have tried it, and it did redirect me to some strange page in a new window. When I closed that page, after that the website worked correctly. I mean every single link I've clicked took me to the right page.
    Hope this helps somehow to resolve this issue!
    All the best!

  5. #5
    drifter8's Avatar
    drifter8 is offline Private Member
    Join Date
    March 2017
    Location
    Bulgaria
    Posts
    1,288
    Blog Entries
    1
    Thanks
    2,739
    Thanked 623 Times in 480 Posts

    Default

    I recommned you to install those WP plugins : " Wordfence" and " Sucuri Seciruty".

    Also take a look on the link - https://gtmetrix.com/reports/roulettetrip.com/4EOD4A2D

    In YSlow score you gonna see somt things.

    My 2 cents,hope being helpful.
    Seven times fall, eight times stand.

  6. #6
    ddm
    ddm is offline Former Member
    Join Date
    July 2006
    Posts
    1,125
    Thanks
    418
    Thanked 470 Times in 287 Posts

    Default

    sanitize your database, lots of these things like to hide inside meta in images, attachments etc. removing malware which is embedded in your DB can be mega tedious / require some code to scale if you have a big site.


    any code snippets u can post (pastebin) so we can work out which nasty you are infected with?

  7. #7
    ddm
    ddm is offline Former Member
    Join Date
    July 2006
    Posts
    1,125
    Thanks
    418
    Thanked 470 Times in 287 Posts

    Default

    Quote Originally Posted by Nenad View Post
    Hi,

    I have tried it, and it did redirect me to some strange page in a new window. When I closed that page, after that the website worked correctly. I mean every single link I've clicked took me to the right page.
    Hope this helps somehow to resolve this issue!
    All the best!
    this sounds like a hack that steals only the 1st click. clear your cookies, click the site from SERPs again, and you will no doubt be redirected to evilsite dot com

  8. The Following 3 Users Say Thank You to ddm For This Useful Post:

    Cash Bonus (5 March 2020), drifter8 (5 March 2020), Nenad (5 March 2020)

  9. #8
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,155
    Thanks
    4,215
    Thanked 9,007 Times in 5,771 Posts

    Default

    You should never need TWO plugins for security, find one the covers the needs you are looking for.

    If you are using a lot of plugins now, consider disabling them all, trying to recreate the instance of the redirect.

    If it stops happening with the plugins disabled, then re-enable them one by one and try and recreate the redirect, to pin down which plugin is causing it, if in fact it is a plugin.

    As others have suggested, securi may help you figure it out, but I would consider the plugin check first, since you should be able to determine fairly fast if it is a plugin causing it.

    ddm made a great point that what is happening might be restricted to first click.

    Rick
    Universal4

  10. The Following 4 Users Say Thank You to universal4 For This Useful Post:

    Cash Bonus (5 March 2020), ddm (5 March 2020), drifter8 (5 March 2020), Nenad (5 March 2020)

  11. #9
    Nenad is offline Public Member
    Join Date
    June 2019
    Posts
    546
    Thanks
    311
    Thanked 155 Times in 128 Posts

    Default

    ddm, many thanks for the explanation.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •