HTTPS redirect bad certification

  • demonmaestro
  • Gold Member
  • Gold Member
  • User avatar
  • Joined: Jun 21, 2006
  • Posts: 484
  • Loc: Conroe, Texas
  • Status: Offline

Post July 20th, 2012, 8:58 am

okay here is a issue from a friends computer.

When going to a HTTPS website it changes the security certification. here is a few screen shots.

picture11.jpg is what it needs to be.

Picture1.jpg is what its showing up on this computer i am working on.
Picture12.jpg is what the ip address of the secure server that it is trying to go through.

i need to figure out how to fix this asap.

Thanks
Attachments:
Picture12.jpg

picture12

Attachments:
picture11.jpg

picture11

Attachments:
Picture1.jpg

picture1

Thanks, Josh --DemonMaestro
www.LilNetwork.com
Fun Website www.ShoutsCloud.com
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post July 20th, 2012, 8:58 am

  • Bigwebmaster
  • Site Admin
  • Site Admin
  • User avatar
  • Joined: Dec 20, 2002
  • Posts: 8922
  • Loc: Seattle, WA & Phoenix, AZ
  • Status: Offline

Post July 20th, 2012, 11:57 am

Looks like he is using Windows XP? Has he installed all of the latest updates, including any optional updates regarding certification paths?

Does he have any trojans, worms, or viruses on his computer -- sometimes that could cause problems like this too. I would also suggest running Malwarebytes.
Ozzu Hosting - Want your website on a fast server like Ozzu?
  • demonmaestro
  • Gold Member
  • Gold Member
  • User avatar
  • Joined: Jun 21, 2006
  • Posts: 484
  • Loc: Conroe, Texas
  • Status: Offline

Post July 20th, 2012, 12:37 pm

Thats been ran and it did find and clean. But I also installed avast and it keeps.poping back saying its originating from schost I believe its called. There was a trogen but avast cleaned it. Yes it is windows xp. Also it is fully updated in windows
Thanks, Josh --DemonMaestro
www.LilNetwork.com
Fun Website www.ShoutsCloud.com
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post July 23rd, 2012, 3:32 pm

This is caused by your original CSR request being signed by a weak MD5 hash. These certificates are no longer support by modern browsers. You need to talk to godaddy and see if they will let you regenerate a new CSR with a stronger MD5 hash and see if they will re-issue it for you.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • demonmaestro
  • Gold Member
  • Gold Member
  • User avatar
  • Joined: Jun 21, 2006
  • Posts: 484
  • Loc: Conroe, Texas
  • Status: Offline

Post July 23rd, 2012, 10:47 pm

that was not an issue. it was a virus and after much more googling me and the owner of the computer figured out how to fix it.

Thanks for all your help! :)
Thanks, Josh --DemonMaestro
www.LilNetwork.com
Fun Website www.ShoutsCloud.com
  • Bigwebmaster
  • Site Admin
  • Site Admin
  • User avatar
  • Joined: Dec 20, 2002
  • Posts: 8922
  • Loc: Seattle, WA & Phoenix, AZ
  • Status: Offline

Post July 31st, 2012, 1:22 pm

If you remember, I am curious what virus caused it in case we have someone else with this issue down the road?

Glad you got it fixed!
Ozzu Hosting - Want your website on a fast server like Ozzu?
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post August 6th, 2012, 1:42 pm

Interestingly enough I caught this rather nasty little virus on July 13th, but it didn't start manifesting itself until after I had rebooted the computer yesterday.

It's called Trojan Horse Dropper.Generic_c.MMI or possibly Trojan.Patchep!sys.

It infects services.exe which is a valid Windows operating system file and needs to be there. It disabled and corrupted Microsoft Security Essentials, AVG finds it but won't touch it because doing so would bugger up the operating system. One of the symptoms was the bogus security cert as noted in this post (My first clue was this morning when I opened my browser to Google and had that message instead of Google's search. I also had browser redirects, popups, etc.

One of the things about it is that it can allow remote access and harvesting of credentials.

Malwarebytes did not find anything related to this. Combofix would get as far as extracting the files, and then this virus would cause it to stop running.

Knowing that it was a windows system file, I decided to stop wasting time on antivirus and just ran an sfc /scannow (System File Checker Utility). It found the corrupted file and replaced it with the original, hence effectively nixing the virus (Reboot was required).

The method I used is detailed in the reply in this post
http://forums.avg.com/us-en/avg-forums? ... &id=212180

Another alternative method is detailed in this link, but it's a little more complicated
http://123seminarsonly.com/Blog/trojan- ... -infection

Good luck. It took me three hours of scans to get to where I could actually identify the virus. After that it was a 5 minute fix to run SFC
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • Bigwebmaster
  • Site Admin
  • Site Admin
  • User avatar
  • Joined: Dec 20, 2002
  • Posts: 8922
  • Loc: Seattle, WA & Phoenix, AZ
  • Status: Offline

Post August 6th, 2012, 3:23 pm

Wow, sounds like a nasty little virus.

Thanks for posting this Mark, I am sure this will help someone down the road. Easy fix, just hard to figure what you had needed to do.
Ozzu Hosting - Want your website on a fast server like Ozzu?

Post Information

  • Total Posts in this topic: 8 posts
  • Users browsing this forum: No registered users and 196 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.