Possible solutions of your questions

  hosting
<< Previous       Account blocked

Question: Account is locked - what you need to do to extend services?
Answer:

came following a complaint, can do something about it to explain to us?

 

Dear abuse team,

 

please have a look perhaps on these offending viruses sites(*) so far.

 

Notice: We do NOT urge you to shutdown your customer, but to inform him about a

possible infection/misbehavior !

 

status: As of ****-**-** **:**:** CEST

 

Please preserve on any reply our Subject:

[clean-mx-viruses-********](**.**.*.**)-->([email protected]) viruses sites (*  so

far) within your network, please close them!  status: As of ****-**-** **:**:** CEST

 

 

http://support.clean-mx.de/clean-mx/[email protected]&response=alive

 

(for full uri, please scroll to the right end.

 

This information has been generated out of our comprehensive real time database,

tracking worldwide viruses URI`s

 

If your review this list of offending site(s), please do this carefully, pay

attention for redirects also!

Also, please consider this particular machines may have a root kit installed !

So simply deleting some files or dirs or disabling cgi may not really solve the issue !

 

Advice: The appearance of a Virus Site on a server means that

someone intruded into the system. The server`s owner should

disconnect and not return the system into service until an

the audit is performed to ensure no data was lost, that all OS and

internet software is up to date with the latest security fixes,

and that any backdoors and other exploits left by the intruders.

are closed. Logs should be preserved and analyzed and, perhaps,

the appropriate law enforcement agencies notified.

 

DO NOT JUST DELETE THE FILES. IF YOU DO NOT FIX THE SECURITY

the PROBLEM, THEY WILL BE BACK!

 

You may forward my information to law enforcement, CERTs,

other responsible admins, or similar agencies.

 

+-----------------------------------------------------------------------------------------------

 

|date                                |id        |virusname        |ip                |domain                |Url|

+-----------------------------------------------------------------------------------------------

|****-**-** **:**:**

CEST        |********        |HEUR/QVM**.*.****.Malware.Gen        |**.**.*.**        |**gadget.ru        |http://**gadget.ru/lowhp/download.php?action=download-direct&file_name=torrent-*******.exe&file_size=***.**KB&file_type=archive&file_url=http://**gadget.ru/skachannye_fajly.exe

+-----------------------------------------------------------------------------------------------

 

 

Your email address has been pulled out of whois concerning this offending network

block(s).

If you are not concerned with anti-fraud measurements, please forward this mail to

the next responsible desk available...

 

 

If you just close(d) these incident(s) please give us a feedback our automatic

walker process may not detect a closed case.

 

explanation of virusnames:

==========================

unknown_html_RFI_php        not yet detected by scanners as RFI, but pure php code for

injection

unknown_html_RFI_perl        not yet detected by scanners as RFI, but pure perl code for

injection

unknown_html_RFI_eval        not yet detected by scanners as RFI, but suspect javascript

obfuscationg evals

unknown_html_RFI        not yet detected by scanners as RFI, but trapped by our honeypots

as remote-code-injection

unknown_html        not yet detected by scanners as RFI, but suspious, may be in rare case

false positive

...javascript.insert        Please pay attention for script code after </html>

unknown_exe        not yet detected by scanners as malware, but high risk!

all other names        malwarename detected by scanners.

==========================

 

 

yours

 

Gerhard W. Recher

(CTO)

 

net*sec UG (haftungsbeschraenkt)

 

Leitenweg *

D-***** Penzing

 

GSM: ++** *** *******

Question: this domain is the script that generates the link to the file via the loader, and the loader (if you don`t uncheck) puts Amigo, mail ru bar. Now this probably complained!
Answer:

this software may not be hosted on our hosting.

ulichnie ttak the rest of the scripts on Your account. in particular, in folder torrent

Question: Exactly the purpose of this folder. Well, if you cannot post, then if you can unlock the account in order for me to pump all the contents to your computer, then most of this post on your hosting I will not!
Answer:

account is unlocked.


<< Previous