Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Sep 2006
    Posts
    212
    cPanel/Enkompass Access Level

    Root Administrator

    Default Potential Virus

    A few days ago, the IT manager from a local bank emailed me and said that one of their employees had gotten a virus from my site (the only site on the server), so they were blocking the site from their system until the virus is corrected.

    I've also noticed the site running slow, in spite of a recent RAM upgrade (from 2G to 4G). I had assumed this problem was just on my end, but then someone emailed me and complained recently.

    The server is semi-managed, so I asked the managing company for help. They ran chkrootkit and found no problems, and didn't see anything unusual running in the background.

    A scan for trojans in WHM resulted this:

    Appears Clean
    /dev/core
    /dev/stderr

    Scanning for Trojan Horses....
    Possible Trojan - /usr/bin/cpan
    Possible Trojan - /usr/bin/instmodsh
    Possible Trojan - /usr/bin/prove
    Possible Trojan - /usr/bin/psed
    Possible Trojan - /usr/bin/pstruct
    Possible Trojan - /usr/bin/s2p
    Possible Trojan - /usr/bin/splain
    Possible Trojan - /usr/bin/xsubpp
    Possible Trojan - /etc/cron.daily/logrotate
    Possible Trojan - /usr/bin/dbiprof
    Possible Trojan - /usr/bin/sa-compile
    Possible Trojan - /usr/bin/sa-learn
    Possible Trojan - /usr/bin/sa-update
    Possible Trojan - /usr/bin/spamassassin
    Possible Trojan - /usr/bin/spamc
    Possible Trojan - /usr/bin/spamd
    Possible Trojan - /usr/sbin/antirelayd
    Possible Trojan - /usr/sbin/pureauth
    Possible Trojan - /usr/bin/ptar
    19 POSSIBLE Trojans Detected

    I know that most of these are OK, but I can't find information on others. Do you guys see anything here that doesn't look right?

    If not, then what's the next step in tracking down the speed issue and virus reported from the local bank? FWIW, I've already gone through the Beginner's Guide on here.

    TIA,

    Jason

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    local bank emailed me and said that one of their employees had gotten a virus from my site
    Have you looked at the actual web page they claim gave them the virus? Certainly it would be reproducible on the next persons visit I would think.

    Personally I'd start there.

  3. #3
    Member
    Join Date
    May 2010
    Posts
    321

    Default

    It could not be your server whats infected, The website you have may have some malicious html code which on view would download or attempt to install things with various pops and such...

    Install ClamAV and give it a good old scan, Check through the index page's and view via notepad and look whats has links or page redirect's in there.

  4. #4
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I'd check the pages on your site for an invisible iframe down the bottom, that's the usual culprit.

    Quote Originally Posted by Infopro View Post
    Have you looked at the actual web page they claim gave them the virus? Certainly it would be reproducible on the next persons visit I would think.
    One would hope that, but not always. Some rootkits load an apache module which randomly inserts viruses, so sometimes they're there and sometimes not.
    White Dog Green Frog - web hosting and web development since 2002
    Blogs: SMB web use cPanel/WHM scripts

  5. #5
    Member
    Join Date
    Nov 2003
    Posts
    119

    Default

    Quote Originally Posted by brianoz View Post
    I'd check the pages on your site for an invisible iframe down the bottom, that's the usual culprit.


    One would hope that, but not always. Some rootkits load an apache module which randomly inserts viruses, so sometimes they're there and sometimes not.
    Some of them even remember who they've already served the virus/exploit code and don't try again on repeat visits.

Similar Threads & Tags
Similar threads

  1. Potential Conference Topics
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 01-22-2008, 04:12 AM
  2. Potential Security Risk?
    By Frankc in forum Security
    Replies: 5
    Last Post: 07-06-2007, 10:52 AM
  3. Potential Security Risk?
    By Frankc in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 07-06-2007, 10:52 AM
  4. clamav 0.90.2 potential problem
    By abubin in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 04-26-2007, 09:23 PM
  5. First ever update-potential problems?
    By Svaha in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-18-2003, 11:22 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube