VIrus removal

All of a sudden I am getting a popup on my main page saying "profx.de/indexs.html" was blocked.  Avg is giving me this.  then another window pops up under talking to "to remove this threat scan computer" and etc.  How can I delete this?  I was updated to 7.0.4

virus.png · 89.7K · 97 views
Quote · 21 Dec 2010

Contact your hosting provider and change all your hosting-related credentials.

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 21 Dec 2010

A few of us have just started a forum about this. I was told by my host that I had to restore from a backup point.

Im attempting this right now.

My signature can beat up your signature!
Quote · 21 Dec 2010

okay but thats not helping me get rid of the virus right now.  I will do that asap but still need to rid myself of the virus

Quote · 21 Dec 2010

I havent had to backup since its a new install, only some mods installed and had updated to 7.0.4 and paid for it so now I have to reinstall and pay again?  I cant really do this, any other options?

Quote · 21 Dec 2010

Im in the same position. Im having to stay with 7.0.2 because upgrading is not an option at the moment

My signature can beat up your signature!
Quote · 21 Dec 2010

I dont understand, I downloaded the site and scanned for the iframe and cant find it, I also looked for the file with the url that it is calling and its not anywhere in my folders

Quote · 21 Dec 2010

Check ALL your .htaccess files. In these files you might find a re-write rule to the mentioned site.

Dedicated servers for as little as $32 (28 euro) - See http://denre.com for more information
Quote · 22 Dec 2010

Well !

or just send me your site link and i will check for you

 

Quote · 22 Dec 2010

Okay, we guess we have found the virus and cleaned it up, please check it out...

It was similar stuff as mentioned by yasenin in this thread - LINK

Probably the attacker can attack again, so better change all your site/email/account/cpanel/ftp/database etc passwords as the hacker probably already have the access to some of them...

Secondly, be careful whom you are providing access to the site. Only provide access to trusted and reputed developers and not to everyone.

 

Thanks

Facebook, Twitter & Instagram Combo - http://bit.ly/1h5CarP
Quote · 22 Dec 2010

@mods4dolphin

Was your site effected? I was testing a mod on your site and now my comp is going crazy....popups everywhere, url redirects....music playing...

Quote · 22 Dec 2010

 

@mods4dolphin

Was your site effected? I was testing a mod on your site and now my comp is going crazy....popups everywhere, url redirects....music playing...

Just checked and yes our site was affected as well...

Just replace the following files:

index.php on the root folder with the original copy to resolve the issue..

index.html under templates folder

index.php under modules folder

and any other files affected...

Not sure how our site got affected as well :(

Is it an exploit in boonex script ??? you never know...

Facebook, Twitter & Instagram Combo - http://bit.ly/1h5CarP
Quote · 22 Dec 2010

Hmmmm .

Now i see maybe alot of people has the same problem !!!!!!!!!!!!!!!!!!!

will i agree with mods4dolphin •

But GUYZZZZZZZZZZZ   I advice You to DO : Full Code SEARCH for :
<script>var zaee="4.5*2,4.5*2,52.5*2,

 

If alot of us is infected it's time to boonex to answer this !!!!!!!!!!!!!!!!!!!!!!!

anyway if you clean it manually is better than restoring a backup i guess and watch .

 

I SUGGEST you if you still has a virus in your pc if you are using Microsoft OS to install microsoft security essentials it will clean your computer specially temp folder.

 

Quote · 22 Dec 2010

The site I have is now infected and I'm trying to figure out how it happened? I've tried to change my admin password. When I put the old and new password I get a wrong new password. The old password works fine. I was thinking of upgrading and buying addtional licenses but to tell you the truth I've been trying to fix this for a week. Looks like I'm going to have to start from scratch.

Quote · 23 Dec 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.