Well, believe it or not, this started affecting us on 17th September and here we are now in November, with the situation worse than it was.
Just to let you know what has happened. I got sick of waiting on hold for customer support, some of it over 3 hours or more! I couldn't get a reply to emails and none of their Ticketing system was ever producing a reply either.
I went to Companies House on line and downloaded their last three years accounts and the names and addresses of their directors etc. Cost less than a tenner for everything that I wanted.
The first thing that I noted was that their profits that they were enjoying a couple of years ago, look like they are now non existant, in my own personal opinion of course and from my own interpretation of their filed and public accounts!
Anyway, I drove down to the "New" Registered office to see someone and found myself at a not so ordinary House, rather run down actually, in my personal opnion and found the Director, who was currently ripping out his kitchen and making way for a new one or something!
I gave him the letter that I had taken with me and then we discussed it. He basically blamed it all on his absence during his holiday, but promised to look into the next day regardless.
I asked how I was going to contect him to get the results and to discuss it further with him and he said "Don't worry, I will ring you". He has as of now, never rung either our work, house or mobile numbers.
Has anything been done, from where I sit, I would say NO ! ! ! Unless you count just more promises to sort it and that they take security very seriously.
Meanwhile three of my sites were infected again. I cleaned them up and they are now waiting for Google to check them before they will put them back on their search engine. However, I have found Google Webmaster tools very informative.
When all this started, they only had about a dozen or so sites infected on their server, now as of today they have 130. The google report is below if you are interested.
The company are adament that it is something on our workstations, presumably meaning that all 130 website hosters have the same virus/trojan on the PC's that they use to upload to their servers.
Needless to say as soon as he said that, we went overboard and scanned everything that moved or didn't move in the house and even wormed the dogs, but found absolutely nothing, so I have asked him what we should be looking out for, what kind of trojan,worm or virus, as he is so sure it is client based and he has yet to reply, as normal!
I would be obliged if someone would take a look at the two Google reports below to see what they make of them..............
The first shows our now clean website, the second is a report on their server and if anyone can shed any light on what "Client side malware" could do this I would dearly love to know!
----------------------------------------
Google Report One on our website that was infected
Safe Browsing
Diagnostic page for manorhousephotos.co.uk
What is the current listing status for manorhousephotos.co.uk?
Site is listed as suspicious - visiting this web site may harm your computer.
Part of this site was listed for suspicious activity 6 time(s) over the past 90 days.
What happened when Google visited this site?
Of the 3 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-10-24, and the last time suspicious content was found on this site was on 2009-10-24.
Malicious software is hosted on 8 domain(s), including search-box.in/, plcscanner.com/, safetysecurityplus.com/.
1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including search-box.in/.
This site was hosted on 1 network(s) including AS35591 (PROVIDERONE).
Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, manorhousephotos.co.uk did not appear to function as an intermediary for the infection of any sites.
Has this site hosted malware?
No, this site has not hosted malicious software over the past 90 days.
How did this happen?
In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.
----------------------------------------
Google Report Two on one of their servers
Safe Browsing
Diagnostic page for AS35591 (PROVIDERONE)
What happened when Google visited sites hosted on this network?
Of the 301 site(s) we tested on this network over the past 90 days, 131 site(s), including, for example, chs-ltd.co.uk/, trades-directory.com/, sailing-by-st-ives.com/, served content that resulted in malicious software being downloaded and installed without user consent.
The last time Google tested a site on this network was on 2009-11-04, and the last time suspicious content was found was on 2009-11-04.
Has this network hosted sites acting as intermediaries for further malware distribution?
Over the past 90 days, we found 3 site(s) on this network, including, for example, scruntlehawk.com/, wilsoncentre.com/, worcesterdaynursery.co.uk/, that appeared to function as intermediaries for the infection of 3 other site(s) including, for example, marbellabam.com/, daynurseries.co.uk/, the-arena.co.uk/.
Has this network hosted sites that have distributed malware?
Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 3 site(s), including, for example, scruntlehawk.com/, wilsoncentre.com/, worcesterdaynursery.co.uk/, that infected 3 other site(s), including, for example, marbellabam.com/, daynurseries.co.uk/, the-arena.co.uk/.
Next steps:
Return to the previous page.
----------------------------------------
H E L P
Does this make sense to anyone at all !!!!
Regards,
Trevor
2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.