By Paul Murray on Wednesday, 01 June 2016
Posted in Technical Issues
Replies 4
Likes 0
Views 782
Votes 0
Hi Stackideas

I am slowly piecing my site back together after a Malware attack.
From the 19 infected files that were on my server I have removed or replaced 16.
Now I only have three left:

Easy Social:

[HEX]obfuscated_globals_2 [27/05/16] /home/finalbug/public_html/administrator/components/com_easysocial/views/themes/view.ajax.php

[HEX]chr_chr_eval_base64 [11/09/15] /home/finalbug/public_html/components/com_easysocial/kg1gsk.php.suspected

Easy Blog:

[HEX]php_spammer_32 [18/04/16] /home/finalbug/public_html/administrator/components/com_easyblog/themes/include24.php

I wonder if some one could confirm if these are even standard SI files?
If not I can remove them?
If they are real Stackideas files...
Could you kindly provide me with a clean version of these files?

I have also bought Akeeba Admin tools and am taking precautions to avoid this happening again.

thanks

Paul
Hello,

[HEX]chr_chr_eval_base64 [11/09/15] /home/finalbug/public_html/components/com_easysocial/kg1gsk.php.suspected
HEX]php_spammer_32 [18/04/16] /home/finalbug/public_html/administrator/components/com_easyblog/themes/include24.php
- These two are not valid file.

[HEX]obfuscated_globals_2 [27/05/16] /home/finalbug/public_html/administrator/components/com_easysocial/views/themes/view.ajax.php
This is a valid file. Clean file has been provided in the attachment.
·
Wednesday, 01 June 2016 10:54
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul,

I am sorry for the delay of this reply. Kindly please find my response to your inquiries below:
Easy Social:

[HEX]obfuscated_globals_2 [27/05/16] /home/finalbug/public_html/administrator/components/com_easysocial/views/themes/view.ajax.php

-> This file is from ours. If you want the clean version of this file, please download the file and replace it to the respective folder

[HEX]chr_chr_eval_base64 [11/09/15] /home/finalbug/public_html/components/com_easysocial/kg1gsk.php.suspected

-> This file is not ours

Easy Blog:

[HEX]php_spammer_32 [18/04/16] /home/finalbug/public_html/administrator/components/com_easyblog/themes/include24.php

->This file also is not ours
·
Wednesday, 01 June 2016 10:54
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Muhammad, Hi Nik

You guys are simply the best.

thanks

Paul
·
Wednesday, 01 June 2016 17:30
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Paul,

You're welcome.
·
Wednesday, 01 June 2016 17:30
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post