Quote:
Originally Posted by obglobal.net
I got this from my hosting service:
I have checked your site and found the following suspicious files:
Code:
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/plugin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/help.php
[HEX]php_nested_base64_510 : [15/09/13] /home/obglobal/public_html/admincp/nsuser.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/index.php
[HEX]php_nested_base64_510 : [17/09/13] /home/obglobal/public_html/admincp/black.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/admin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/forum.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/index.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/showthread.php
Can someone PLEASE tell me how to clean these out? I really have no idea what to do and I'm desperate.
--------------- Added [DATE]1379430244[/DATE] at [TIME]1379430244[/TIME] ---------------
Yeah, I did.
Can I change my passwprds via cPanel, do you know?
|
Firstly I would check all those files, check them against what is uploaded when you do an install, then check them against what is those folders for each plugin.
Delete any that you cannot find.
off the top of my head this one looks a bit suspicious
/home/obglobal/public_html/admincp/black.php