Rohan Posted July 13, 2005 Posted July 13, 2005 Dear Friends, Apparently there is a virus (JAVA_BYTEVER.C and JAVA_BYTEVER.A) in my phpBB forum index page at: http://www.lankalibrary.com/phpBB/ As you open this page the virus get downloaded to your PC. This is detected in Symantec, eTrust and with office scan. I have already got few complains on this. Can somebody please explain to me how I can remove this virus from this page? Thank you in advance, Rohan Quote
TCH-Thomas Posted July 13, 2005 Posted July 13, 2005 Hi and welcome to the forum, Rohan. I am not sure if this is the best/easiest way but I would download the phpbb folder and its database or a backup of the whole site to my pc and then locally scan it with Norton etc to see which file that have the virus and go from there. Quote
TCH-Thomas Posted July 13, 2005 Posted July 13, 2005 One additional note... I see that you run version 2.0.11 while the latest version is 2.0.16 so I would strongly suggest that you update immediately. Quote
TCH-BillH Posted July 13, 2005 Posted July 13, 2005 It looks like someone has updated your forum for the topic that reads: "If you are looking for information, please post your request here!" and added the link for the PHP file in that. You should be able to update that title and remove it. I wouild also do as Thomas suggested and upgrade your forum. Keep us posted! Quote
Rohan Posted July 13, 2005 Author Posted July 13, 2005 It looks like someone has updated your forum for the topic that reads: "If you are looking for information, please post your request here!" and added the link for the PHP file in that. You should be able to update that title and remove it. I wouild also do as Thomas suggested and upgrade your forum. Keep us posted! <{POST_SNAPBACK}> Hi BillH, You are a genius! As you correctly said somebody has added a hidden link to a php file in that specific place. I just removed the link and now the problem is solved. How did you find that out? Thanks a lot! Rohan ps: I also upgraded to 2:0:15 version. I still do not have the option for 2:0:16! Quote
TCH-BillH Posted July 13, 2005 Posted July 13, 2005 Hi Rohan, I did a search on the source code for the IP address that was used in the link, to download the PHP file. I saw that it occurred right after that subject title. Glad things are working well again and that you upgraded the BB to 2.0.15. That will help! Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.