Page 1 of 1

Malware attack

Posted: Wed Aug 31, 2011 9:16 am
by Pete Eeles
Many of you will have seen a warning - indicating that UK Butterflies has been attacked, resulting in some modified files.

All files have now been replaced to their original state, all passwords changed, the hosting provider informed, and a request to review the website logged with Google before it is revalidated and considered "safe".

I'll post another message here once I get confirmation that all is well again!

Cheers,

- Pete

Re: Malware attack

Posted: Wed Aug 31, 2011 10:06 am
by Pawpawsaurus
Blimey, you don't hang about, do you? :)
I saw my first 'Reported Attack' warning this morning. As it seemed persistent, I was about to report it to you. No need now.

Thanks,

Paul

Re: Malware attack

Posted: Wed Aug 31, 2011 3:00 pm
by Pete Eeles
Google has now confirmed that the site is "clean":

"Status of the latest badware review for this site: A review for this site has finished. The site was found clean. The badware warnings from web search are being removed. Please note that it can take some time for this change to propagate."

Thx for your patience!

Cheers,

- Pete

Re: Malware attack

Posted: Mon Sep 26, 2011 9:40 pm
by Susie
When I log in to this site I am being warned that it is insecure, whatever that means. :?

Re: Malware attack

Posted: Mon Sep 26, 2011 9:46 pm
by Pete Eeles
Hi Susie - just checked the site over and everything seems OK.

What browser are you using?

Cheers,

- Pete

Re: Malware attack

Posted: Mon Sep 26, 2011 9:57 pm
by Susie
I'm using Internet Explorer 9 and it's still doing it.

Re: Malware attack

Posted: Mon Sep 26, 2011 10:08 pm
by Pete Eeles
Hmmm. Can't reproduce this. What specific message are you getting (this might allow me to track this down)? Thx!

Anyone else seeing this?

Cheers,

- Pete

Re: Malware attack

Posted: Mon Sep 26, 2011 10:17 pm
by Susie
Hmmm, I am wondering if it is some bug my computer has picked up. When I try to log in a box appears which says warning, the site, UKButterflies.co.uk is insecure blah blah blah about information being provided not being encrypted and gives me three options; to allow, disallow or mark the site as secure. The name rapport appears in the top right hand side of the box.

Anyway, too late to worry about all that stuff now. :)

Re: Malware attack

Posted: Tue Sep 27, 2011 6:25 am
by Michaeljf
Susie wrote:Anyway, too late to worry about all that stuff now. :)
Hi Susie,
if it helps at all - when I log into my work emails from home (I work in a college) I get a similiar message about the college site and our site is fine. So I think it's a bit of bo**ocks really. :wink: Perhaps someone doesn't pay subscription fees to the local mob..
Michael

Re: Malware attack

Posted: Tue Sep 27, 2011 9:19 am
by Pawpawsaurus
Susie wrote:When I try to log in a box appears which says warning, the site, UKButterflies.co.uk is insecure blah blah blah about information being provided not being encrypted and gives me three options; to allow, disallow or mark the site as secure. The name rapport appears in the top right hand side of the box.
Susie,

Is this:
http://www.trusteer.com/insecure-website-warning
the warning you're seeing? If so, then it looks like a third-party security application which is reporting the supposed risk, rather than malware on your PC.

The 'Products' link at the top of that page explains all. It seems that: "Rapport is a lightweight security software solution that protects web communication between enterprises, such as banks, and their customers and employees."

My guess is that it was told about the recent attack, but doesn't know that all is now well with UKB. There's a 'report this to us' link at the bottom right of the page I've linked to, for reporting safe sites. [Maybe a job for Pete?] The first drop-down box on the form may give you a clue to where this software has come from.

HTH,

Paul

Re: Malware attack

Posted: Tue Sep 27, 2011 9:46 am
by MikeOxon
Susie wrote:The name rapport appears in the top right hand side of the box.
Several Banks promote the Rapport software, to improve security, and provide links to install it, when you set up on-line banking.

Unfortunately, this software does have side effects and many people have had a lot of problems, at least with the earlier versons. It developed a reputation for slowing your computer down and giving false positives - as you have found. It is quite difficult to remove the software, if you decide to, but you should be able to find instructions on the web.

Mike

Re: Malware attack

Posted: Tue Sep 27, 2011 10:46 am
by Susie
Hi all,

Thanks, Michael.

Yes, Paul, that is the message I was seeing. I've clicked on the site being safe so I don't think it will come up again.

Hi Mike. I don't know who added that bit of software as there are quite a few of us who use this computer so I think I will just leave things as they are but I am grateful for the help and advice.

Re: Malware attack

Posted: Tue Sep 27, 2011 10:49 am
by Paul Wetton
Rapport totally crashed my PC when I loaded it up via my bank account.
It had to be removed using their website if I remember correctly.
It couldn't be removed directly from the PC.