View Single Post
  #245  
Old 07-08-2009, 07:30 AM
 
chilll33 chilll33 is offline
 

Senior Member
  
Join Date: Oct 2003
Location: Miami, FL
Posts: 100
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

I was hacked on 7/6/09, all my index.php, home.php were changed, my site is new, so it was easier to spot the files changed since I did not work on them that day. I also discover there was a virus in my PC which was not picked up by the antivirus, but was able to remove with AVG anti-rootkit.

The virus was not in my system no longer than 2 days.

I believe this virus is related to this issue since my computer was having problems around this date.

the files picked up:

Path: C:\Windows\System32\drivers\MSIVXjoevvtideftywmffu mitipxlcpgecuyf.sys Description: Hidden driver filePath: C:\Windows\System32\drivers\MSIVXjoevvtideftywmffu mitipxlcpgecuyf.sys Description: Hidden FilePath: C:\Windows\System32\MSIVXcount Description: Hidden FilePath: C:\Windows\System32\MSIVXcsiowexpxmydnbpnyqjcobywt myuytne.dll Description: Hidden FilePath: C:\Windows\System32\MSIVXcwdnrvsthgsiolbctqqomernh exsgpcj.dll Description: Hidden File

you might also find a folder c:\program files\sys\
__________________
Core version:
5.3.2.7

PHP:
5.6.29
MySQL server:
5.5.5-10.0.27-MariaDB-cll-lveĀ  (InnoDB engine support enabled)
Web server:
Apache
Operating system:
Linux
XML parser:
found
GDLib:
found (0)
Translation driver:
Database
Curl version:
7.29.0
Reply With Quote