infected File? - Post ID 302645

User 47216 Photo


Registered User
210 posts

My server's virus protector just recently sent me a notification of malicious files on my server - they were specifically listed as a file in my exported form builder folder ... cartapp_v1/phphosted/checkoutdirect.cls/php

The file does not appear to have been tampered with or altered since I uploaded it because the date is still the same as the date I uploaded the file. Anyone else ever have this happen?
Attachments:
User 2699991 Photo


Registered User
5,490 posts
Online Now

Captain Ron wrote:
My server's virus protector just recently sent me a notification of malicious files on my server - they were specifically listed as a file in my exported form builder folder ... cartapp_v1/phphosted/checkoutdirect.cls/php

The file does not appear to have been tampered with or altered since I uploaded it because the date is still the same as the date I uploaded the file. Anyone else ever have this happen?


First you should check with your hosting service technical support and get them to check out the files.

You probably should delete the WFB and all assoviated files (depending on what technical support say/do)
You should then be able to reload the clean files from your PC.

You need to address this A.S.A.P something similar happened to a client (not WFB) Google took the website down completely and even after a new one was uploaded, it took a long time for Google to start crawling and indexing the site again.
Mastering The Understanding With Hands-On Learning
NEW TO "COFFEECUP SITE DESIGNER" FOUNDATION 6 FRAMEWORK?
STUCK ON SOMETHING?

LEARNING & UNDERSTANDING "THE HOW TO"? THE WHY'S & THE WHEREFORE'S?
WITH WAYAN'S STEP BY STEP TUTORIALS

Contact me
https://rsd-tutorialscom.coffeecup.com/index.html
User 47216 Photo


Registered User
210 posts

Well I deleted the file from the car app folder and re initiated the san and no threats were found. Then I went into form builder redid the form entered in my paypal identity token uploaded all the new files, did a scan again and it shows the file as being infected again. Thinking this is a false positive as it it happeneing with every website on my VPS that is using the WFB to accept payments (same file on all of them)

Have something to add? We’d love to hear it!
You must have an account to participate. Please Sign In Here, then join the conversation.