Quote:
Originally Posted by aspen1018
No they are not. Have no idea how to clean that up though
|
Those ARE the malware, as a closer look at the request reveals:
Quote:
GET /tmp/api.php HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://www.vspotlounge.com/forums/forum.php
Accept-Language: en-US
X-Download-Initiator: html="doc 0C40 win AAA0; html frame appendChild"
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0) PTST/153
Accept-Encoding: gzip, deflate
Host: finansecity.pl
DNT: 1
Connection: Keep-Alive
|
And appear to be in /tmp/api.php
The second one is in a different location:
Quote:
GET /tmp/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://www.vspotlounge.com/forums/forum.php
Accept-Language: en-US
X-Download-Initiator: html="doc 0C40 win AAA0; html frame appendChild"
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0) PTST/153
Accept-Encoding: gzip, deflate
Host: finansecity.pl
DNT: 1
Connection: Keep-Alive
|
These files are not part of vBulletin. I think your board has been hacked and you should follow all the protocols for cleaning it.