[SOLVED] Possibly infected file from Gallery3

leschek

Joined: 2006-07-29
Posts: 44
Posted: Sat, 2014-06-28 18:35

Today my website showed me, instead of gallery and forums, "Account suspended" sign. I emailed support to ask them what is wrong and they told me that some of the files are infected and on the list with a few files was one file from gallery:

gallery3/modules/gallery/helpers/gallery.php

I checked the file and it seems to be OK (I'm not programmer) so I wrote back to the hosting and here is what they wrote me:

Quote:
Hello,

As part of our security concern we have installed a new antivirus system in the server which does the scanning by default. These files has been scanned and seems to be infected. Please consult with the developer for rechecking all the scripts and remove those infected files to avoid further suspension.

Regards
....
....

It would be great if someone could check the file, so I can write back to hosting and have my site online again.
P.S. I attached the supposedly infected file

AttachmentSize
gallery3.zip3.68 KB
 
floridave
floridave's picture

Joined: 2003-12-22
Posts: 27300
Posted: Sun, 2014-06-29 02:18

They have to be a bit more verbose in the boiler plate response
"and seems to"
does not give much to go on.

Anyway... you are at 3.08 and you should upgrade to 3.09 anyway. There is no change in that paticular file from 3.08 to 3.09 other than the version #.

So they will have to give some details or their "new antivirus system" has some incorrect positives.

Dave
_____________________________________________
Blog & G2 || floridave - Gallery Team

 
spags

Joined: 2010-03-26
Posts: 120
Posted: Sun, 2014-06-29 10:53

Sounds like some false positive detections to me. Check the file with your own antivirus software and you will probably find it is fine (do so for the other files they identified as well). If you can't get anywhere with the hosts support ask the strategic question, "Could you please identify what malware it is actually infected with?", just so that a person actually has a look. If they can give an answer, do some research on what that malware is and if it is obviously absurd you can go back to them with such a response.

 
leschek

Joined: 2006-07-29
Posts: 44
Posted: Mon, 2014-06-30 18:33

Thank you very much for help and information how to "deal" with hosting. Hosting already unsuspended my account and the gallery (and the rest of the site) is working again.