Quote:
Originally Posted by glorify
I do believe that was the file that was getting tagged with virus scan as well.
|
You mean it has the HTML_DLOADER.GUR as said below:
http://www.trendmicro.com/vinfo/viru...%2EGUR&VSect=T
I think this hack needs to be pulled because you add 1+1 you will get 2 so this script needs flagged immediately and if you read carefully there and see the .cn sites it's referring too after running a scan here on a local computer with Trend you will get the following results:
Quote:
Virus Scan Results 2/1/2007 EPC2
Time Event Source Type Virus Name File Name First Action
12:02 Manual Scan File HTML_DLOADER.GUR Upload contents to your forum root\admincp\mp3player_admin.php (C:\XEON_vbMp3_Player.zip) Clean Success
12:02 Manual Scan File --- C:\XEON_vbMp3_Player.zip Clean Success
|
As you see it was caught by TrendMicro and NOD32 Server A/V...
So why the iframe in the admin file as asked going to the China website which now the file inde1.htm doesn't exist any longer...
Oh well just a heads-up for the rest