<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[FrontAccounting forum — Virus detected]]></title>
		<link>https://frontaccounting.com/punbb/viewtopic.php?id=5413</link>
		<atom:link href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=5413&amp;type=rss" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in Virus detected.]]></description>
		<lastBuildDate>Wed, 24 Dec 2014 17:34:21 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Virus detected]]></title>
			<link>https://frontaccounting.com/punbb/viewtopic.php?pid=21874#p21874</link>
			<description><![CDATA[<p>These files do not belong to frontaccounting. They are probably having some sort of base64_decode / gzinflate / eval code encrypted virus. Tere will be some image files as well that contain malicious code.</p><p>Check your files/folders ownerships/permissions (you appear to be using Windows because of backslash separators so it may not apply) and htaccess / apache conf directives for vulnerabilities.<br />Such malicious code can be placed even beyond your webroot as well.</p><p>Do you have data in your FA (is it in production use)? - if so, take professional help.<br />Also check if you have additional CoAs, extensions, themes and languages installed apart from item images.</p><p>Take a backup of the following files after taking sql dumps from say phpMyAdmin:<br /></p><div class="codebox"><pre><code>.htaccess
config.php
config_db.php
installed_extensions.php
lang/installed_languages.inc
company/0/installed_extensions.php
company/0/images/*.jpg
company/0/images/*.png
company/1/installed_extensions.php
company/1/images/*.jpg
company/1/images/*.png
....
....</code></pre></div><p>Wipe out all files from your webroot and do a fresh install and then restore your sql and above files.<br />Change all your SFTP/SSH/FTP/FA passwords.</p>]]></description>
			<author><![CDATA[null@example.com (apmuthu)]]></author>
			<pubDate>Wed, 24 Dec 2014 17:34:21 +0000</pubDate>
			<guid>https://frontaccounting.com/punbb/viewtopic.php?pid=21874#p21874</guid>
		</item>
		<item>
			<title><![CDATA[Virus detected]]></title>
			<link>https://frontaccounting.com/punbb/viewtopic.php?pid=21872#p21872</link>
			<description><![CDATA[<p>Hi,</p><p>avg detected 3 infected file in my frontaccounting backup, they are</p><p>&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\purchasing\includes\infobeB4.php&quot;;&quot;Infected&quot;<br />&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\modules\import_items\cookielJy3.php&quot;;&quot;Infected&quot;<br />&quot;&quot;;&quot;Virus identified PHP/Agent.4, faccount\inventory\includes\infokO04.php&quot;;&quot;Infected&quot;</p><p>Can I just delete/overwrite them?</p><p>Than you<br />Eric</p>]]></description>
			<author><![CDATA[null@example.com (ericta)]]></author>
			<pubDate>Wed, 24 Dec 2014 15:56:19 +0000</pubDate>
			<guid>https://frontaccounting.com/punbb/viewtopic.php?pid=21872#p21872</guid>
		</item>
	</channel>
</rss>
