virus on server adding malacious code on pages

Sedang Disiapkan Disiarkan Jul 22, 2009 Dibayar semasa penghantaran
Sedang Disiapkan Dibayar semasa penghantaran

A while back we had a problem with a virus breakout on our website. We thought we had eliminated it, but it once again modified some of our most important files, including our [login to view URL] page. What it seems to be doing is adding js code to certain files, so far all we know about is our main index file and the index file of a subdomain. We think this came from a security hole in our photo gallery (Coppermine Photo Gallery), so the search will start there.

As far as we know, this has effected us in 2 locations, although there may be more we do not know about. First, '[login to view URL]' (from www/[login to view URL]) and 'language="javascript">$=' (from www/poker-network/[login to view URL]). It looks like the code was manually added but perhaps one of our many JS files or something else have been corrupted?

We need a professional to help diagnose, remove this virus AND prevent it from coming back. NOTE - We do not feel comfortable giving someone we do not know full FTP access to our server. We will create a copy of the main directory we believe the problem resides in and you can search and make the fixes here. The winning bidder must understand that they have to find and fix this issue without ftp access. (Although you will not have full ftp access, you can work in real time with someone who will have ftp access [over gtalk, msn, aim, skype, etc.])

Please see attached pictures for screen shots:

SS1 - User not able to view our homepage

SS2 - Code added to [login to view URL] (line 355)

SS3 - Code added to network page (line 198)

SS4 - Virus popup from network page

Keselamatan Web

ID Projek: #473656

Tentang projek

5 cadangan Projek jarak jauh Aktif Jul 24, 2009

5 pekerja bebas membida secara purata $317 untuk pekerjaan ini

shakoush2001

Certified Ethical Hacker, can help.

$150 USD dalam 0 hari
(27 Ulasan)
5.5
visu14

Hi.. Am Expert in web security.. Please check PM..

$175 USD dalam 2 hari
(9 Ulasan)
4.2
vizh

I have already encountered the virus and have the experience of its removal. There are nuances that I sent in the PM.

$60 USD dalam sehari
(0 Ulasan)
0.0
hudli

The problem seems to lead deeper than just to the html files. Please see PM.

$1000 USD dalam 5 hari
(0 Ulasan)
0.0