Viewing 8 posts - 16 through 23 (of 23 total)
  • Author
    Posts
  • #13211
    Dj Buik
    Member

    Fixed from the /forum site but NOT the main /index.php site.

    http://www.claessonedwards.com/index.php

    #13212
    George
    Member

    Seems to be OK now 🙂

    At least, NOD stops complaining about it!

    #13213
    didac
    Participant

    No, at this moment, main site is infected.

    Please remove the malware!

    Thanks 😉

    #13214
    Leif
    Keymaster

    What the hell!

    We did remove it. It was fine. Now it’s back.

    Perhaps we need to look into a different hosting provider.

    ///Leif

    #13215
    JesseG
    Member

    Can confirm it’s NOT fixed. This isn’t hard tho. 😉 Just re-launch your browser, and go to ceaudio.com/claessonedwards.com and the Java execution request still pops up.

    #13216
    Boki
    Member

    i told you… ‘that’ (this) whole server need full reinstall. Nothing else will help! It will be always comming back, soon or later.

    #13217
    JesseG
    Member

    Also check to see what is in CRON, to see if any php scripts are there. But if the box was pwnt, it’s pretty easy to hide stuff from the web admin user/s. That being said, this was done with an exploit, and if that wasn’t patched, then… yeah. 😉

    There’s probably some code running somewhere in php that’s just re-"installing" this to the public pages. The first part of the battle would be to figure out what exploit script is being used via php, and find out where it does everything by default. The php script for the root access probably has a name and credits in it.

    #13218
    Dj Buik
    Member

    [quote author=”Leif”]We did remove it. It was fine. Now it’s back.[/quote]

    Did you also remove it from the main index.php page?

    Because i do not get the error anymore from the /forum directory.

Viewing 8 posts - 16 through 23 (of 23 total)
  • The forum ‘Breakaway Professional Products – [discontinued]’ is closed to new topics and replies.