GGS Shell Checking System ===Shell Check List=== /home/bozauto/public_html//wp-includes/class-http.php: Suspicious(fsockopen): $request_order = array( 'curl', 'streams', 'fsockopen' ); /home/bozauto/public_html//wp-includes/class-simplepie.php: Suspicious(fsockopen): * fsockopen() file source /home/bozauto/public_html//wp-includes/js/plupload/license.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-includes/js/tinymce/plugins/spellchecker/classes/GoogleSpell.php: Suspicious(fsockopen): $fp = fsockopen("ssl://" . $server, $port, $errno, $errstr, 30); $data = shell_exec($cmd); /home/bozauto/public_html//wp-includes/js/tinymce/plugins/spellchecker/rpc.php: Suspicious(fsockopen): $socket = fsockopen($url['host'], intval($url['port']), $errno, $errstr, 30); /home/bozauto/public_html//wp-includes/js/tinymce/license.txt: Suspicious(Hacker): library `Frob' (a library for tweaking knobs) written by James Random Hacker. /home/bozauto/public_html//wp-includes/SimplePie/File.php: Suspicious(fsockopen): * Supports HTTP 1.0 via cURL or fsockopen, with spotty HTTP 1.1 support /home/bozauto/public_html//wp-includes/SimplePie/Sanitize.php: Suspicious(fsockopen): var $force_fsockopen = false; /home/bozauto/public_html//wp-includes/SimplePie/Misc.php: Suspicious(r57): case 'isoir57': /home/bozauto/public_html//wp-includes/class-snoopy.php: Suspicious(fsockopen): if($fp = fsockopen( /home/bozauto/public_html//wp-includes/class-phpmailer.php: Suspicious(root@): public $From = 'root@localhost'; /home/bozauto/public_html//wp-includes/class-smtp.php: Suspicious(fsockopen): $this->smtp_conn = @fsockopen($host, // the host of the server /home/bozauto/public_html//wp-includes/class-pop3.php: Suspicious(fsockopen): $fp = @fsockopen("$server", $port, $errno, $errstr); * This class uses the Unix `diff` program via shell_exec to compute the /home/bozauto/public_html//wp-includes/ID3/module.audio-video.riff.php: Suspicious(hacked): MDVD Alex MicroDVD Video (hacked MS MPEG-4) (www.tiasoft.de) /home/bozauto/public_html//wp-includes/ID3/getid3.php: Suspicious(open_basedir): // sys_get_temp_dir() may give inaccessible temp dir, e.g. with open_basedir on virtual hosts /home/bozauto/public_html//wp-includes/ID3/getid3.lib.php: Suspicious(Windows-1251): case 'Windows-1251': /home/bozauto/public_html//wp-includes/ID3/module.audio.ogg.php: Suspicious(base64_decode): $flac->setStringMode(base64_decode($ThisFileInfo_ogg_comments_raw[$i]['value'])); /home/bozauto/public_html//wp-includes/ID3/module.audio-video.quicktime.php: Suspicious(hacked): $QuicktimeSTIKLookup[5] = 'Whacked Bookmark'; /home/bozauto/public_html//wp-includes/class-feed.php: Suspicious(fsockopen): function __construct($url, $timeout = 10, $redirects = 5, $headers = null, $useragent = null, $force_fsockopen = false) { /home/bozauto/public_html//wp-includes/class-IXR.php: Suspicious(base64_decode): $value = base64_decode($this->_currentTagContents); RewriteRule ^index\.php$ - [L] /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-http.php: Suspicious(fsockopen): $request_order = array( 'curl', 'streams', 'fsockopen' ); /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-simplepie.php: Suspicious(fsockopen): * fsockopen() file source /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/js/plupload/license.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/js/tinymce/plugins/spellchecker/classes/GoogleSpell.php: Suspicious(fsockopen): $fp = fsockopen("ssl://" . $server, $port, $errno, $errstr, 30); $data = shell_exec($cmd); /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/js/tinymce/plugins/spellchecker/rpc.php: Suspicious(fsockopen): $socket = fsockopen($url['host'], intval($url['port']), $errno, $errstr, 30); /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/js/tinymce/license.txt: Suspicious(Hacker): library `Frob' (a library for tweaking knobs) written by James Random Hacker. /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/SimplePie/File.php: Suspicious(fsockopen): * Supports HTTP 1.0 via cURL or fsockopen, with spotty HTTP 1.1 support /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/SimplePie/Sanitize.php: Suspicious(fsockopen): var $force_fsockopen = false; /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/SimplePie/Misc.php: Suspicious(r57): case 'isoir57': /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-snoopy.php: Suspicious(fsockopen): if($fp = fsockopen( /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-phpmailer.php: Suspicious(root@): public $From = 'root@localhost'; /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-smtp.php: Suspicious(fsockopen): $this->smtp_conn = @fsockopen($host, // the host of the server /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-pop3.php: Suspicious(fsockopen): $fp = @fsockopen("$server", $port, $errno, $errstr); * This class uses the Unix `diff` program via shell_exec to compute the /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/ID3/module.audio-video.riff.php: Suspicious(hacked): MDVD Alex MicroDVD Video (hacked MS MPEG-4) (www.tiasoft.de) /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/ID3/getid3.php: Suspicious(open_basedir): // sys_get_temp_dir() may give inaccessible temp dir, e.g. with open_basedir on virtual hosts /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/ID3/getid3.lib.php: Suspicious(Windows-1251): case 'Windows-1251': /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/ID3/module.audio.ogg.php: Suspicious(base64_decode): $flac->setStringMode(base64_decode($ThisFileInfo_ogg_comments_raw[$i]['value'])); /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/ID3/module.audio-video.quicktime.php: Suspicious(hacked): $QuicktimeSTIKLookup[5] = 'Whacked Bookmark'; /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-feed.php: Suspicious(fsockopen): function __construct($url, $timeout = 10, $redirects = 5, $headers = null, $useragent = null, $force_fsockopen = false) { /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-includes/class-IXR.php: Suspicious(base64_decode): $value = base64_decode($this->_currentTagContents); /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-content/themes/twentythirteen/fonts/LICENSE.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-admin/includes/class-ftp-pure.php: Suspicious(fsockopen): * FTP implementation using fsockopen to connect. /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/wp-admin/includes/file.php: Suspicious(fsockopen): * The priority of the Transports are: Direct, SSH2, FTP PHP Extension, FTP Sockets (Via Sockets class, or fsockopen()) /home/bozauto/public_html//wp-content/upgrade/wordpress-3.tmp/wordpress/license.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-content/uploads/2013/06/RED-SPADE-MALE-MEDIUM-166x300.jpg: Suspicious(c99): !VU4 !VdSbӔS 9[PI2)̺|HެnHQZ p4c995**dg5>hZ|~r1+cuI5]OQdi.nfin'_?| :>8ϞE~Lx/ E4DC.;?y8r|?T$wշsecPM+[P/B+G RHQSeUۋ1(\F=?e7㗆i 26?yƣ'O޾`xν7!R0V V^ca8,hG+dPWjR2M}cuc41;qUԮj5Sނ*[Mej$ye.GLn#ڹ:^R5Qe p2J۔WW/sK=d2D7\~h'܋g}+t;Mvec/={s?='7IEuu\ϙsVڷ4II:zZuUFrw={ s6$G /home/bozauto/public_html//wp-content/uploads/2013/06/BOZLOGO-1100x100.png: Suspicious(c99): P@)~h$ ]*eb ;Ĥv,o2++4ٽsd1[>H3ָMkn;q\E /home/bozauto/public_html//wp-content/uploads/2013/06/TRUCK-LAMPS-684x100.jpg: Suspicious(c99): ӭ|uj=d~TSr~Y_^է¢8Ob;y<3|+:; NPwG= Ĭ:u4 2PGҙ&RT|zWQlALq9F_U54&C1`m Kc99<6̄ HUb>ї,oث7`iTLnx~GpK$&' $eҁH $YЫv /home/bozauto/public_html//wp-content/uploads/2013/05/Untitled-2.png: Suspicious(c99): x* NPR㜅PcsGڷDp"[/="xRsTbK(8w KhS(]G#&'M7D*kuk+!LK t-wlܧuyZ3ǥO# ,i!c99p'2}EΘ+W+u*̞3W#G?Ζ 2ET 0On \Ijq<[˒.IR֙19f'1~9Ap"\3l،8M[XI)2}3 Zh`Z1 2_) 3#*nr0ڧ=>x;Q27Վ1Ɠ v'W8ެİ9Os䈣lh9}dgJpfiB K QӜ:֋ܞdSXc׮~XSԃ1c`A\vq{2"HdlrČ*O*Ub$aֵDD ?-Ib`G^ wn;rJ`p8Čde >lcghqlep8ӿjktv!M9ϯԌY0`#XrHߒ~RZfo@6pCc99cϲMsEup+Fe /home/bozauto/public_html//wp-content/plugins/wp-e-commerce-call-for-price/license.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-content/plugins/akismet/akismet.php: Suspicious(fsockopen): if( false != ( $fs = @fsockopen( $http_host, $port, $errno, $errstr, 10 ) ) ) { /home/bozauto/public_html//wp-content/plugins/akismet/admin.php: Suspicious(fsockopen): if ( !function_exists('fsockopen') || !function_exists('gethostbynamel') ) { /home/bozauto/public_html//wp-content/plugins/nextgen-gallery/lib/rewrite.php: Suspicious(hacker): //DD32 recommend : http://groups.google.com/group/wp-hackers/browse_thread/thread/50ac0d07e30765e9 /home/bozauto/public_html//wp-content/plugins/nextgen-gallery/lib/imagemagick.inc.php: Suspicious(passthru): // very often exec()or passthru() is disabled. No chance for Imagick /home/bozauto/public_html//wp-content/plugins/use-google-libraries/gpl-2.0.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/screenshot-4.png: Suspicious(JIKO):  u8%%mZ,,+б '162".!MAAAXDUUu -ZC~Ғ<Q5Ngiy3&.:!]F%ڶmbap;v`*{;g~-wlhV栫ʢ򚐨АȨGhHBJb|R5kv}ƙ7$.>%)1%?/p{Nօ VӺUbIIAyEYH32,:"* /TRuA^F#-f| (VgΜ/ܹfz~ű<>GqDJJJF=p%6 )1qY;«k"cXJIKO/Z˯Æ:xa=z hݶCyYeAaNEβ|ɪߖLɎIzpkKK,MNID4 L{;Vq]2UtTUU͚5kƌߔ)S:v옐 䬿ݻs*Jqq֭[Y;Ə+A3 /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-shipping/ups_20.php: Suspicious(base64_decode): /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-includes/nusoap/nusoap.php: Suspicious(fsockopen): $this->debug('calling fsockopen with host ' . $host . ' connection_timeout ' . $connection_timeout); /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-includes/nusoap/class.soap_transport_http.php: Suspicious(fsockopen): $this->debug('calling fsockopen with host ' . $host . ' connection_timeout ' . $connection_timeout); /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-includes/nusoap/class.soap_server.php: Suspicious(fpassthru): fpassthru($fp); /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-includes/nusoap/class.soap_parser.php: Suspicious(return base64_decode(): return base64_decode($value); /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-admin/display-upgrades.page.php: Suspicious(fsockopen): if ( false != ( $fs = @fsockopen( 'instinct.co.nz', 80, $errno, $errstr, 10 ) ) ) { /home/bozauto/public_html//wp-content/plugins/wp-e-commerce/wpsc-merchants/library/googleresponse.php: Suspicious(base64_decode): base64_decode(substr($_SERVER['HTTP_AUTHORIZATION'], /home/bozauto/public_html//wp-content/gallery/slider1/alternator1.jpg: Suspicious(c99): yt;]bC4kIHgTCxIlX-\V(!T၂zXHdd#J.v-!RKq̮J.X´mܸ(.TZ9Ǘ R#%Jc99ƒxI#IA (DdXTF/[I> /home/bozauto/public_html//wp-content/themes/twentythirteen/fonts/LICENSE.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. /home/bozauto/public_html//wp-config.php: Suspicious(c99): define('LOGGED_IN_KEY', 'obxnc996865vt14dvlhwyu1ejlu62lsca3xogfnle8shfk4oqtoepopdbco52wxc'); /home/bozauto/public_html//wp-admin/includes/class-ftp-pure.php: Suspicious(fsockopen): * FTP implementation using fsockopen to connect. /home/bozauto/public_html//wp-admin/includes/file.php: Suspicious(fsockopen): * The priority of the Transports are: Direct, SSH2, FTP PHP Extension, FTP Sockets (Via Sockets class, or fsockopen()) /home/bozauto/public_html//oldsite/jotform/lib/recaptcha/recaptchalib.php: Suspicious(fsockopen): if( false == ( $fs = @fsockopen($host, $port, $errno, $errstr, 10) ) ) { /home/bozauto/public_html//oldsite/scripts/fsbb/fsbb.php: Suspicious(base64_decode): $val=base64_decode($value); /home/bozauto/public_html//license.txt: Suspicious(Hacker): `Gnomovision' (which makes passes at compilers) written by James Hacker. ===ClamAv Check List=== /home/bozauto/public_html/wp-content/plugins/wp-e-commerce/wpsc-core/js/swfupload/swfupload.swfobject.js: SecuriteInfo.com.HTML.Framer.16090.14174.12502.UNOFFICIAL FOUND /home/bozauto/public_html/wp-content/themes/mantra/header.php: SecuriteInfo.com.JS.Redir.16479.28327.28701.UNOFFICIAL FOUND /home/bozauto/public_html/wp-content/themes/mantra/footer.php: SecuriteInfo.com.JS.Redir.16479.28327.28701.UNOFFICIAL FOUND ----------- SCAN SUMMARY ----------- Known viruses: 4876407 Engine version: 0.99.1 Scanned directories: 491 Scanned files: 5993 Infected files: 3 Data scanned: 100.69 MB Data read: 202.62 MB (ratio 0.50:1) Time: 62.493 sec (1 m 2 s) ===Maldet Check List=== {CAV} SecuriteInfo.com.HTML.Framer.16090.14174.12502 : /home/bozauto/public_html/wp-content/plugins/wp-e-commerce/wpsc-core/js/swfupload/swfupload.swfobject.js {CAV} SecuriteInfo.com.JS.Redir.16479.28327.28701 : /home/bozauto/public_html/wp-content/themes/mantra/header.php {CAV} SecuriteInfo.com.JS.Redir.16479.28327.28701 : /home/bozauto/public_html/wp-content/themes/mantra/footer.php {CAV} SecuriteInfo.com.JS.Agent-2798 : /tmp/sess_0qs85i3rornm6a32idmsrrpcd5 {CAV} SecuriteInfo.com.JS.Agent-2798 : /var/tmp/sess_0qs85i3rornm6a32idmsrrpcd5 ===Image Check List=== ./oldsite/images/untitled.bmp: PC bitmap, Windows 3.x format, 17 x 28 x 8 ./oldsite/images/arrow02.gif: PC bitmap, Windows 3.x format, 17 x 28 x 8