Sep 10 2009

Dealing with “This Site May Harm Your Computer” Notice

So your site got hacked. Google identified some malware on it and put “This site may harm your computer” notice next to your site listings in SERPs.

It happens so often today that you don’t even need to be too surprised: no panic, just take action.

Steps to take:

  1. Remove the Malware (check the source code of your pages);
  2. Change your FTP-passwords;
  3. Contact your hosting provider to let them know they possibly have some secure leak and make sure they have taken some action (that’s also a good way to make sure your hosting provider is worth the money you are paying);
  4. Check your site with blacklistdoctor.com (re-branded as Dasient.com) or unmaskparasites.com to get an idea about which files are infected
  5. Browse your site using various user agents and possibly proxy servers to make sure all is working fine;
  6. Request a malware review via Webmaster Tools.

Request Malware review

More reading:

32 Responses to “Dealing with “This Site May Harm Your Computer” Notice”

  1. Dealing With “This Site May Harm Your Computer” Notice: http://bit.ly/Ft9Os

  2. RT @AnueSystems: RT @FSecure: How to take action if your site has been hacked. http://bit.ly/Ft9Os

  3. RT @FSecure: How to take action if your site has been hacked. http://bit.ly/Ft9Os

  4. Ran says:

    Hi Ann,

    Good practical post. Another super important step is to scan your personal computer for any nasty surprises in case your password(s) have been compromised. When writing the reconsideration request to the google team, take the time to note the prevention you’ve taken, step by step.

  5. Kerry Dye says:

    @Ran – the request a review for Malware isn’t the same as the reconsideration request – there is no option to enter additional information, it is basically just a request for a rescan of your site. I wrote about the effects on your SEO only a couple of weeks ago at http://www.vertical-leap.co.uk/blog/this-site-may-harm-your-computer-google-warning-message-and-seo-effects/

  6. Thomas J. Raef says:

    Ran is correct. So far this year 88% of websites hacked have been from a virus on a PC with FTP access to the hacked site.

    The virus works in a variety of ways.

    First, it knows where common FTP programs store their usernames and passwords. Many of them don’t encrypt the login credentials so finding the file, reading it and sending the stolen login credentials to a server is no big task.

    When the server gets the login information it downloads the website to it’s server, infects the code, then re-uploads it or sometimes it just simply infects just the index files; .php, .html, .htm, etc.

    The second way the virus works is by installing a keyboard logger. This will catch the login credentials of the people who were told not to have their FTP software store the information.

    The third way is the virus “sniffs” the outbound FTP traffic and since FTP transmits all data, including username and password, in plain text, it’s easy for the virus to see and steal the credentials.

    The fourth way is that the virus injects it’s infectious code into the data stream of the FTP traffic as it’s leaving the PC. This method leaves no clues in the log files on the web server because the FTP traffic is only coming from a valid IP – that of the website owner/designer/master.

    Typically the only way to clean this virus is install a different anti-virus program than what is currently installed because the virus has learned how to evade detection of the currently installed anti-virus program.

    By installing a new anti-virus program, you can find the virus and remove it.

    Many have had good success with AVG, Avast, Avira or Malwarebytes. If you’re already using one of these, use one of the other ones as it has to be different or you may not find and remove the virus.

  7. abilitydesigns says:

    I’d chime in with extra points as people often do not know where the source of infection lies.

    * Seek help in google website owner’s help forum for hacked sites / sites with malware warning or stopbadware org’s forum

    *Check your site with blacklistdoctor dot com or unmaskparasites dot com to get an idea about which files are infected.

    *Scan and clean your PC before you try accessing your site again with FTP to avoid getting into a loop.

    -AD

    Ann Smarty Reply:

    Thanks, AD :) Just added your tips to the post…

  8. liposuction says:

    The second way the virus works is by installing a keyboard logger. This will catch the login credentials of the people who were told not to have their FTP software store the information.thanks a lot.

  9. Shiju Alex says:

    If you have been infected, after all the above steps, it shall be wise to change FTP passwords immediately after FTP access. You may check your FTP logs to ensure that attempts for login has not originated from suspicious IPs that are not yours.

    Another means of infection could be through a vulnerable code that is already hosted. It could even be the web application that you use. So it would be good to identify the infected files and check the web logs for suspicious activity (well, this is a tedious task). Search the web for vulnerabilities in the web application that you are using and apply updates as required.

  10. Lax transportation says:

    very nice post Many of them don’t encrypt the login credentials so finding the file, reading it and sending the stolen login credentials to a server is no big task.

  11. cardboard boxes says:

    The only way to clean this virus is install a different anti-virus program than what is currently installed because the virus has learned how to evade detection of the currently installed anti-virus program.

  12. SM@SeoNext says:

    Amazing post…thanks a lot for this informative post.Really a nice post.

  13. conveyancing solicitors uk says:

    I’m seeing the same thing. I’m guessing it’s a google problem.thanks a lot.

  14. limousines gold coast says:

    The virus works is by installing a keyboard logger. This will catch the login credentials of the people who were told not to have their FTP software store the information.

  15. play roulette says:

    The only way to clean this virus is install a different anti-virus program than what is currently installed because the virus has learned how to evade detection of the currently installed anti-virus program.

  16. chat says:

    Let’s become a friend: ) Thanks

  17. Ameet Ranadive says:

    Hi Ann,

    Thanks for the great post! This is Ameet from Dasient, the creators of the blacklistdoctor.com tool you referenced in step 4. We have re-branded the BlacklistDoctor tool under the Dasient name, so feel free to scan your site for malware on the dasient.com.

    We also provide some resources for learning more about how and why malware attacks occur on our website, for anyone interested in learning more.

    Finally, you may consider signing up for monitoring of your website using our free blacklist monitoring or premium malware monitoring services.

    Thanks,

    Ameet

    Ann Smarty Reply:

    Thanks, I added it to the post

  18. business mobile phones says:

    The virus works is by installing a keyboard logger. This will catch the login credentials of the people who were told not to have their FTP software store the information.very informative post thanks.

  19. first home buyer says:

    It could even be the web application that you use. So it would be good to identify the infected files thanks a lot.

  20. Underfloor heating says:

    It could even be the web application that you use. So it would be good to identify the infected files and check the web logs for suspicious activity (well, this is a tedious task).

  21. 125cc Motorbikes says:

    I’ve seen a lot of Ran mentioned recently – viruses that are geared to scrape login data from your FTP programs and then run amok.

    Thanks for the online checking tools – not seen those before!

  22. Restaurant POS says:

    Thanks for information about which steps taken if this error comes. I bookmark this post.

  23. Court Reporters says:

    Good post about which steps taken when site got hacked. Thanks for helpful information.

  24. y8 says:

    I’ve use the blacklist doctor and it works fine to me..

  25. pockie ninja says:

    websmaster tools from google helps a lot…

  26. ben 10 says:

    one of the good tools from google webmaster is you can test your site if it has mall ware on it. great job from google..

  27. Y8 says:

    Don’t even know what to say on this topic. So much ideas are mixed in my head after reading it. Very problematic article I think

  28. Y8 says:

    great post

    This is a very informative article.I was looking for these things and here I found it. I am doing a project and this information is very useful me.

  29. Ben10 says:

    cool article thanks dostlar

  30. Kids Games says:

    tskler guzel b1r paylas1m sagolun arkadaslar