<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[FrontAccounting forum — Virus detected]]></title>
	<link rel="self" href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=5413&amp;type=atom" />
	<updated>2014-12-24T17:34:21Z</updated>
	<generator>PunBB</generator>
	<id>https://frontaccounting.com/punbb/viewtopic.php?id=5413</id>
		<entry>
			<title type="html"><![CDATA[Re: Virus detected]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=21874#p21874" />
			<content type="html"><![CDATA[<p>These files do not belong to frontaccounting. They are probably having some sort of base64_decode / gzinflate / eval code encrypted virus. Tere will be some image files as well that contain malicious code.</p><p>Check your files/folders ownerships/permissions (you appear to be using Windows because of backslash separators so it may not apply) and htaccess / apache conf directives for vulnerabilities.<br />Such malicious code can be placed even beyond your webroot as well.</p><p>Do you have data in your FA (is it in production use)? - if so, take professional help.<br />Also check if you have additional CoAs, extensions, themes and languages installed apart from item images.</p><p>Take a backup of the following files after taking sql dumps from say phpMyAdmin:<br /></p><div class="codebox"><pre><code>.htaccess
config.php
config_db.php
installed_extensions.php
lang/installed_languages.inc
company/0/installed_extensions.php
company/0/images/*.jpg
company/0/images/*.png
company/1/installed_extensions.php
company/1/images/*.jpg
company/1/images/*.png
....
....</code></pre></div><p>Wipe out all files from your webroot and do a fresh install and then restore your sql and above files.<br />Change all your SFTP/SSH/FTP/FA passwords.</p>]]></content>
			<author>
				<name><![CDATA[apmuthu]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=364</uri>
			</author>
			<updated>2014-12-24T17:34:21Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=21874#p21874</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Virus detected]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=21872#p21872" />
			<content type="html"><![CDATA[<p>Hi,</p><p>avg detected 3 infected file in my frontaccounting backup, they are</p><p>&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\purchasing\includes\infobeB4.php&quot;;&quot;Infected&quot;<br />&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\modules\import_items\cookielJy3.php&quot;;&quot;Infected&quot;<br />&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\inventory\includes\infokO04.php&quot;;&quot;Infected&quot;</p><p>Can I just delete/overwrite them?</p><p>Than you<br />Eric</p>]]></content>
			<author>
				<name><![CDATA[ericta]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=5299</uri>
			</author>
			<updated>2014-12-24T15:56:19Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=21872#p21872</id>
		</entry>
</feed>
