GOOD INFO .STREAM

Filezilla FTP Virus / Malware / Adware / Website Parasite: How to Spot It and What to Do

by Johnny Brezenhauer

Has somebody told you that your legit and innocent website makes their anti-virus programs flash warnings and block your site? And on closer inspection, have you noticed that your website, upon loading, first connects to some other irrelevant site, sometimes making your page take longer to load? Have you been desperately scratching your head, wondering what causes this? Is it your web host that is corrupt, or have servers infected with spyware?

Well, so have I and fortunately I can tell you now what this is, how to spot it and how to get your site back on track.

When a visitor to my site first told me honestly that my site is full of viruses, I had to do a lot of headscratching on what could be causing this. Could it be that the 3rd party advertisement displayer is showing image ads that contain viruses? Was it perhaps a free script I had used, or a free player I had integrated, or is the problem that my web host's server has been infected?

Well, with the help of my host, we have managed to find the problem. At this time I do not know what this virus / malware / adware / worm / trojan / spyware / password stealer / parasite does or even what to call it, or where your site contracts it, or what the purpose of it is supposed to be after it infects one's website, but as we have come to know the internet and its criminals, it can of course be nothing good for the infected website and its owner. I'm assuming for the time being it's some kind of spyware script stealing passwords and collecting identity information from computers browsing the innocent victimized sites.

One of the sites this virus loads something from is rec-creations.com, but sometimes it also connects to other uncalled for sites. When opening rec-creations.com in my browser, it seems to be the website of a provider of children's playground equipment. However, the malicious script is definitely downloaded from their site.

Note that most likely, rec-creations.com got infected somehow with this malware, and they are therefore also an innocent victim. It's likely they have no idea that their website is being used as a host by the malware infectors, to spread the malware from.

The illegal running of a script on and downloading of something from rec-creations.com when we open our own site, is caused by a script, usually in our index.html file but I suppose it can be in any html file or any other web page file of one's site.

Now before you open your index.html file in your html editor to look for it, don't bother, for it is NOT there. You will not see it in your local file. It is written into the file by the virus somewhere between the transfer from your computer (perhaps by infected FTP software or browser when uploading via control panel, though I can't say which for sure) and being on your host's server.

Even though you uploaded a file that is clean on your computer, if you now open that page in your web browser, the first thing you'll notice is that your status bar at the bottom of your browser may say "Waiting for rec-creations.com..." or "connecting to" or "transferring from" the parasite website. It may slow down the downloading speed of the page, or it may be so quick that you don't even pick up that your browser had connected to another site before finishing the opening of your page.

However, if you now right-click and choose "View Page Source", you will spot this malicious script HIDDEN ANYWHERE on your page among the lines of code:

In the photo below, it was hidden in the page body, however, in another infected page, it was hidden right after another script in the header details, making it extremely hard to spot.

How and at what stage did it get added to the page code? That for now is the mystery; if somebody who knows more about it reads this, please comment and share the details.

UPDATE: It seems likely a downloaded version of Filezilla is the culprit that adds the code to files during FTP upload. ALWAYS only ever download Filezilla from the official site, and not from any third parties that may have tinkered with it. Personally I've just stopped using Filezilla altogether for safety.

UPDATE #2: I have now stumbled upon posts by internet users that say Filezilla officially contains viruses and malware, so could it be that it wasn't that somebody else tinkered with a Filezilla install file and offered it online to others in order to infect them, but that Filezilla's own people is using it to distribute malware? Sad and sick.

Anyway, how to fix the issue is simple:

It would appear that not only does Filezilla alter the html files you upload in Filezilla in order to add the malicious lines, but also that your password have been sent off somewhere to be used to add the offending lines of code to your pages and reupload them so altered, even if you yourself are not using Filezilla anymore.

Fortunately it seems if you install and run Malwarebytes, an anti-malware program, Malwarebytes will pick up the malware and you can remove it from your computer.

Once you have run Malwarebytes and removed the malware on your computer that stole your website control panel's password, you MUST CHANGE YOUR WEBSITE CONTROL PANEL'S PASSWORD or your web pages will simply get infected again.

Now, if you're sure that there's no password stealing malware on your computer, as for your infected website files on your website's server, delete the infected file, for example index.html off of your web host's server, and upload the clean original (make sure it is clean of course) again. Completely refresh your website in your browser, usually by pressing Ctrl + F5, and check the status bar for connecting to any strange sites. If you can't spot any, right click and check the source code again. The parasite script should be completely gone from the entire source code.

Now your site should be safe again for browsing.

People also see:

TELEFUNKEN tablet 10.1IN 3G TEL-1013GIQA: My impressions

AI ROBOT working in OFFICE


Download GAMES for PC straight from Japan! Browse games here


Do your COMPUTER SHOPPING at B&H! Laptops, desktops, Macs, Hardware components & more


Hello Coding - Anyone Can Learn to Code


Domain names & hosting available at 1-GRID


Check out these funky computer & gaming keyboards!


Browse the web privately with ATLAS VPN. All the benefits a VPN has to offer for a ridiculously low price!


Wolfeye Remote Screen is a software that allows to see live computer screen remotely via the internet using a web browser. See what your employees or children are doing on the computer!


Full-Stack Web Development In 7 days


VR GAMING COMPUTERS for sale! Gaming laptops & more


Take your cybersecurity to the next level with NORDVPN. Get secure and private access to the internet.


Get a new tablet computer


Browse LAPTOPS to suit every need! Basic, Work & Business, Creative, Gaming, MacBooks & more


Try NORTON 360. Enhanced security for your devices and VPN for online privacy


SOUNDCARDS for computer for sale. Creative Labs Sound Blaster, Startech, Sabrent & more


Unlock the Future of Tech and Gaming with the Complete Unity/Unreal AI and ChatGPT Bundle+


Buy TABLETS, COMPUTERS, MEMORY CARDS & MORE ONLINE! Shipped internationally


Domain names & hosting available at 1-GRID


Domain Name Success Kit


Empower Your Child's Future with Our Ultimate Kids Coding and Game Development Bundle


Browse iPads, Tablets & E-Readers for sale! Check out great deals


Buy 3D PRINTERS & FILAMENT here! Shipped worldwide


Buy MICRO SD & TF CARDS here! Shipped worldwide


The Complete AI Digital Artist Masterclass


The Complete Excel, AI and Data Science Mega Bundle


The Complete Python, Machine Learning, AI Mega Bundle+


Godot Game Development Machine Learning Masterclass


EGroupware - Online Collaboration Software


Raspberry Pi for Beginners (Mac+PC)


Google Hacks VSeries


TikTok Marketing - viral Secrets of TikTok


Becoming Nora An AI Transformation is a must-read for anyone interested in the fascinating world of artificial intelligence and its potential impact on humanity.


450+ Mega Fonts Bundle


Get COMPUTER PRINTERS here! Inkjet, Laser, Large format, 3D printers, Labels, ID cards, Barcode printers, Cartridges & toner & more


Endless Internet Profits


Learn COMPUTERS & TECHNOLOGY: Computer Backup, Computer Repairs, Data-Recovery: What You Need, Electronics Stores, External Hard Disk Drive, How To Build a PC, iPhone Downloads, Malware Or Spyware , Online Backup


Become a DIGITAL NOMAD: Take your laptop and start traveling around the world!

 GoodInfo.Stream - where the best info is FREE!

Panasonic HC-VX985M: Good 4K camera on a budget


Bluetooth operating instructions for AIM CZ201 2.1CH Multimedia Speaker System


QQ5 full HD 170 Degrees Ultra wide angle MINI DV video camera: My review


AIM Alarm Clock Radio, model ACR9 - Very nice bedside radio clock!


Panasonic HC-VX985M 4K video camera review


A small bluetooth speaker with good bass and great sound: HY-40 Super Bass Speaker


XCEED PULSE Portable Radio Clock - my favorite!


Mobicel V4 cellphone product exploration


AIM ADV1010 portable 10" LED Monitor and DVD Player: Good for a while


ENZER E5768P7 Portable DVD Player


AIM ADVD7P Portable Entertainment System


ENZER E5178 DVD Player


TELEFUNKEN 8GB Mp4 Player TMP-888B


National Panasonic RF-947 Y/B Radio


AIM ACD300 Portable CD Radio


WIKKID WIK031 Mp3 Player


EVEREADY Classic FM Radio


TELEFUNKEN TMH-771A Hi-Fi


OTTIMO PCD-7200 PORTABLE CD PLAYER Review


Panasonic RX-DU10 Portable Stereo System first day impressions


RHAPSODY TV Radio


CHARGE T5-S portable wireless speaker


SHOX BOOM BOX by Tevo


L8STAR BM60 world's smallest flip phone review & discussion


Big sound from a small speaker: JBL GO2 Portable Bluetooth Grab and Go Speaker


Santa's Trading Co. Candle Lamps Battery Operated


Bright Light stick up bulb: Portable and Wall-mountable lamp, 3 LED. Very useful!


Eurolux 500W Portable Floodlight: Good for Workspace & Amateur Video


12V light for solar powered / battery powered lighting: Jinwang LED DC 12V 1W-3W Switched light, model HB11SET/B


The Power Of Wind


LED Head Lamp Super Power


What is 3D printing?


Why is Google Search becoming totally useless?


PANTUM P2200 Mono Laser Printer: Fast printer 20 pages per minute, Processor 600MHz, Memory 64MB


4TB Seagate Expansion Hard Disk Drive


How to get into the BIOS on a Windows 10 computer


Store your music, photos & videos on the PREMIO 32GB Micro SDHC Card (including SD Adapter)


ASUS F540S laptop computer Review


ADATA 8GB Classic C008 USB Flash Drive


PREMIO 32GB Micro SDHC Card + SD Adapter


Android tablet keeps downloading unwanted apps


Pimp My Keyboard with Twin Seven Fun Keyboard Stickers


How to open .docx file


Connex SLIM BOOK 14" Intel Atom Quad Core Laptop: My review


ASUS F540S laptop computer


TOSHIBA NB500 notebook laptop computer


Why can you sometimes not reach certain websites you know are there?


30,000 Photos - Royalty Free Images Conveniently on CD


Sonicfire Pro 5 Hangs when Trying to Open Project: Quick Fix


How Steinberg and Other Software Companies Encourage Software Piracy


How to create a sitemap FREE for your website


Filezilla FTP Virus / Malware / Adware / Website Parasite: How to Spot It and What to Do


GadgetTech Computer USB 4 Port Hub: Good Idea Made Bad


Digitech USB 2.0 Combo 6 Port USB Hub with Card Reader


Payperpostforum.com: My Experience & Review As a Forum Owner


Windows 95: The Big Release


Mocha -> LiveScript -> JavaScript


HP Deskjet 2050A All-in-One Printer: May Not Work on Your Computer


CONNEX SWIFT BOOK Laptop Computer product exploration


CONNEX Slim Book laptop computer product exploration


CONNEX Slim Book, CONNEX Swift Book laptops Reviews


What is the password for the wifi at Cabana Beach Resort, Umhlanga?


How to download YouTube videos FREE


How to change the video playback speed with Windows Media Player


YouTube video screen flickers in firefox! Help!


How to show and remove unavailable videos from your YouTube Playlist


What is the hardware specifications of the iLIFE Digital ZEDPC Portable All-in-One computer?


How to switch your freehostia.com website to https


How Politics Affected 20,000 Leagues Under the Sea


Who is Aesop of Aesop's Fables?


How did National Geographic start?


Arabian Nights


The Lost Ark of the Covenant: The Remarkable Quest for the Legendary Ark, by Tudor Parfitt


Die Gestewelde Kat leesboek vir 8 - 9 jaar oue kinders


Garfield!


The Garfield Super Selection comic book by Jim Davis


Drink Fresh Healthy Orange Juice with the Mellerware Cyclone Citrus Juicer


LOGIK Egg Boiler with Poaching Tray


SELECTS Cappuccino Frother


Nostalgia Electrics Movie Time Popcorn Maker OFP-501


Ottimo Stand Blender


Ottimo F-718 1.5 Litre Cordless Kettle


AIM Halogen Heater Model AHH9 PO No. 00101709


Logik Hepa Vacuum Cleaner Tp-vc612b


BUSHBABY BUTANE CAMPING STOVE portable gas burner: Really useful 4 cooking, demonstrations & travel


BUSHBABY BUTANE CAMPING STOVE portable gas burner: Really useful 4 cooking, demonstrations & travel


GOLDAIR GTAC-708 USB MINI AIR COOLER - Don't overfill it with water!


The Smuggling Route For South African Rhino Horn


Butterflies: Colourful, Flying Little Creatures


Bob Martin Tick & Flea Dog Spot Tick & Flea Treatment


Cough Medicine for Maltese Poodles: No Such Thing?


Introduction to Training Your Dog


What caused the green gooey discharge in my maltese poodle dog's eyes?


Bob Martin Arthripet tablets for bone and joint stiffness in pets


Cool and humidify your air with H9 PORTABLE FOLDING HYDRATING 185° FAN


Kill Worms in Your Intestines with Mebendazole


DriBuddi hot air clothes dryer review: Is It Any Good and Should I Get One?


FASHION MEN STYLING CREAM - So what do you use it for?


How to make an auto-subscribe link to your youtube channel


ORAIMO SOUNDFLOW OBS-72D WIRELESS SPEAKER Triple Thumping Bass 360-degree colourful LED light REVIEW


Load more...


(c) Goodinfo.Stream
Goodinfo.Stream may earn commissions for referrals to products on Amazon.com & others
Disclaimer