What is troxy.php ?

Ben10

New Member
I found a file in my public_html named troxy.php when i download this it terminated by NOD32 here is the detail
Code:
Scanner">Real-time file system protection</COLUMN>
Object">file</COLUMN>
Name">C:\Documents and Settings\***\Desktop\New Text Document.txt</COLUMN>
Threat">PHP/Rst.R trojan</COLUMN>
Action">cleaned by deleting - quarantined</COLUMN>
User">NT AUTHORITY\SYSTEM</COLUMN>
Information">Event occurred during an attempt to access the file by the application: C:\WINDOWS\system32\NOTEPAD.EXE.</COLUMN>

first i run this on my domain and i see a page on this page i see all the information of my forum like all directory all files also database name .i am worried and i think this file should be used by hackers .
here is the code of that file in this zip if you want to see then disable antivirus software and then see it and also tell me what is it
 
Remove it immediately and change the database user password, and make it a good one w/ randomize characters and lots of them.. Scour the rest of the directories in public_html for any other unrecognized files/folders.
 
Thanks for your kind reply can you guide me where i can change the database user name and password ?
 
Change it in your cPanel. You want to change the password for the database user. After you change it, put the same password on your config.php.
 
Grinderhand said:
Change it in your cPanel. You want to change the password for the database user. After you change it, put the same password on your config.php.

Sorry i don't find this option in my cpanal
i am using cPanel Build11.24.4-RELEASE 36167
and unable to find any option to change pass in mysql databases
 
Change your FTP password too! If you have any MODs installed that are "out of date" get rid of them or upgrade to latest and greatest. Somehow that prick got onto your system and you need to button it up to keep him out now.
 
Change your FTP password too!

Thanks, Blue. Already covered in another post.

Sorry i don't find this option in my cpanal
i am using cPanel Build11.24.4-RELEASE 36167
and unable to find any option to change pass in mysql databases

cPanel -> MySQL databases -> scroll to the bottom to find Users section -> delete the current user, then make a new user with the same user name OR different user name if you so desire for even better security and a new password for that user, and give them full permissions to the database when asked. Then edit your config.php entering the new username (if you made one) and the new password.
 
bluescorpion said:
Change your FTP password too! If you have any MODs installed that are "out of date" get rid of them or upgrade to latest and greatest. Somehow that prick got onto your system and you need to button it up to keep him out now.

Thanks bro i am using alot of mods
here they are
Code:
Advanced BBCode Permissions 4.0 beta 1 Lets you set Usergroup Permissions for BBCode. 
Advanced Horoscopes Hack 2.0.1 Automatic Daily Updated Horoscopes Hack by Hasann 
Advanced Ip Ban Manager 0.2.1b Allows advanced management of IP bans. 
Ain - Advanced Prevention Copies and Shading 3.0 Prevent shading and copies of certain groups 
AJAX Tabbed Latest Threads 1.0 Displays latest thread of defined forums in tabs with ajax. 
AJAX Tabbed Latest X Objects 1.3 HASANN 
Allow Signature per Forum 1.0.1 This hack adds the option to disable the Signature per forum - by Hoffi 
Angular Advertisements 1.0 Advanced Angular Advertisements for vBulletin by Hamed Haddadian (www.gtpland.com) 
Arrange subforum 1.00 Sub-Forums in columns 
Auto Delete/Move Thread After X days. 2.0 Delete thread that have been created earlier than X days. 
Auto Tagger 1.0 Auto tag new threads with keywords from title. 
Automatic Tagging 1.0 Tries to tag untagged threads. 
Avatars Per Forum 1.0.0 Avatars Per Forum 
Chief First Post - Every Page 1.1.0 Chief First Post - Every Page 
Corner Peeler 2 0.1.0 Insert ads, specials and surprises into top-right/top-left corner peelers2... 
Cyb - Advanced 'New Posts' 2.1 Cyb - Advanced 'New Posts' 
Cyb - Advanced Forum Statistics 6.6.1 Cyb - Advanced Forum Statistics 
Cyb - Attention Zero-Posters 1.5 Cyb - Attention Zero-Posters 
Cyb - Auto Birthday Greeter 1.4 Cyb - Auto Birthday Greeter 
Cyb - Auto Reply 1.2 Cyb - Auto Reply 
Cyb - Check If Already Posted 1.6 Option to check if the same/similar thread already exist when posting new one 
Cyb - Login To User Account 2.3 Cyb - Login To User Account 
Cyb - Moderating Stats 1.6.1 Cyb - Moderating Stats 
Cyb - PM System Enhancements 1.5 Cyb - PM System Enhancements 
Cyb - Prevent Newbies from Posting to Wrong Forum 2.2 Cyb - Prevent Newbies from Posting to Wrong Forum 
Cyb - Sub-Forum Manager 2.5 Cyb - Sub-Forum Manager 
Cyb - Visitors in Last X Hours 2.4 Cyb - Visitors in Last X Hours 
Default User Text Formatting 1.0 Allow users to chose there default text formatting from (User CP). With Zero Query! 
Doublepost Prevention Plus 1.3 This Modification prevents doubleposts by merging post together, if the last poster of a thread tries to post again. 
Enhanced Image Captcha 2.2b An image based captcha system to prevent bots signing up to your forum. 
Force Users to Read a Thread 2.0 This hack allows you to specify a thread that you would like users to read. They would not be able to do anything else on the forum before reading it. 
Forum Category Icons 1.0.0 Allows you to set an icon image for each of your forums on the forum home page (Categories only). 
Forum Home Mp3 by ArTanGeL 1.0 Play your mp3 in Forum Home of your vBulletin board. 
Google Adsense 1.0.0 Display ads that are targeted to your site's unique content. 
GTPrivate Messages Enhanced Listing 3.7.0.0 Adds private message previews on pm list display - brought to you by http://vbulletin.org. 
HBD Corner Banner 1.0 This mod will add an absolute corner banner to a corner of choice. 
HBD information bar 1.0 HBD information bar that prompts your user with important information in a hidden block thats revealed once toggled!. 
HBD JQuiry spoiler bbcode 1.0 Adds [spoiler]spoiler[/spoiler] bbcode option (with admin settings) 
HBD Ultimate Posting Tools 1.0 Adds helpful posting tools to your forum editors. 
HelpCenter 1.00 A Support Ticket System! 
HS Advance Forum Home Announcements 1.0.0 Easily managable Announcements box on your foum home page! 
HTML Email 1.0.0 Sends HTML Enabled e-mail. 
ibProArcade for vBulletin 2.6.7 ibProArcade - professional Arcade System for vBulletin 
Icons for UserCP 1.2 Add icons to your UserCP Navigation Bar. 
Inactive User Reminder Emails 1.1.3 Sends emails out to inactive users encouraging them to re-visit the forum 
Inferno vBShout 2.5.1 Real time shoutbox 
Intro On Register 1.0.0 Submits an intro when a member registers. 
Invitation System 2.0.3 Allow users send invitation to everybody 
Islamic-Life - Glorious Qur'an 1.27 Displays the Glorious Qur'an in Arabic and interpretation of the meaning in 25 different languages. 
IWT - Time Spent Online 1.0.1 This will add a counter in that shows how much time your users have spent online on the site. (EX: 5 Months 2 Weeks 1 Day 15 Hours 44 Minutes 33 Seconds) 
IWT - vBExperience - ibProArcade Highscorer Points 1.1.0 This addon for vBExperience will award points to highscorers of the ibProArcade. 
Latest X Threads on Forum Home 2.5 This hack will show the latest threads on your forum home page 
MARCO1 PRODUCT Hide links for visitors VERSION 2 2.00 Guests Not see links in Post,Search,Thread Preview,Quotes,Archive,Print version,Reply,Signature,post VERSION 2 WITH CONTROL PANEL 
Members who have Posted 3.7.001 Display members who have posted in the forum. 
Moderator Application System 2.1.1 Moderator Application Form and Rating System 
Must Pass Quiz to Post 1.0 Requires users to demonstrate their knowledge before posting. 
MySmilies VB 3.7.004 Personal Smilies for your users 
nCode Image Resizer 1.0.1 Automatically resize posted images 
Nexia's Channels Navigation 1.0.0 A different way to navigate thru your site. Replacement for the Forum Jump. 
NoSpam! 4.0 NoSpam! allows you to specify a set of questions which members are required to answer correctly at registration, eliminating the ability of spam bots to register at your forums and post unwanted messages. 
Notifications Background Image Final Version This will change the Navbar where the Notifications Box is to a different background image 
Photobucket Image Upload 1.0 This will enable you to upload your Photobucket Images/Videos to your post. 
Post Thank You Hack 7.6 Post Thank You Hack 
Quick Editor Improver 1.0 This hack add more controls to quick editor by that you wish. by Hamed Haddadian (www.gtpland.com) 
Radio and TV 2.0 A radio and TV stations library. 
Reputation Report 1.1 Reputation Report 
Separate Sticky and Normal Threads 1.0.5 Separate Sticky and Normal Threads 
Similar thread check v2 2.0 Check for similar thread before starting a new one. 
Site Map 1.0.4 A Site Map for your site, similar to the one on vbulletin.org. 
Smilies in Quickreply 3.6.x Show Smilies in Quickreply. 
SMS (Text Messaging) Capabilities 1.1 Adds SMS (text messaging) capabilities to your forums. 
Template Modification System 1.1.2 This Modification allows automatic managament of Template-Modifications 
Thread Title Coloring 1.02 Enables you to customize the color of your thread titles. 
Threads rating 1.4.1 Threads rating inside threads 
Threads Started by User in Postbit & Profile 1.0.1 This Product Counts the Threads Started by a User & Displays in their Postbit & Profile 
Time Greeting 1.00 Changes "Welcome" to "Good Morning/Afternoon/Evening" in the navbar 
Top Nav Bar 1.0 Top nav bar for extra drop down menues. 
User Anniversary 1.00 show user-anniversary on FORUMHOME 
Usergroup Color Bar 2.1.0 Usergroup Color Bar Modified by TheProphet 
Username HTML Markup 2.0   
vBExperience 3.8.3 Calculate activity of your users 
vBExperience - Post Thank You Hack Integration 1.1.0 Gives points for using and getting thanks. 
vBExperience Level 1.0 vBExperience Level 
vBGuides: Seasonal Effects 1.0.0 Add seasonal weather effects to your forum 

vBSEO 3.2.0 vBulletin SEO 
vBSEO :: Sitemap Generator 2.5 Generate a Google & Yahoo Sitemap for your Forums 
vBulletin Blog 1.0.5 Personal web log, integrated with vBulletin. 
View threads started on postbit 1.0.1 You can add a little line (under number of posts) which shows the number of threads the poster have made. 
vLkn-Sponsored Links 1.0.0   
vMoods By ZONE365.COM 1.1.3 Allows users to have simple moods for their profile. 
WarLion online/offline 2.9 Agrega Offline Online class 
Who Has Read a Thread. 3.7.007 Display members who have read a thread. 
ZH - Meta Tags 1.0.4 This SEO product improves your search engine page rank! 
 [AJAX] Who's Online 1.3 Refresh list of active users without reload main page
 
Grinderhand said:
Thanks, Blue. Already covered in another post.



cPanel -> MySQL databases -> scroll to the bottom to find Users section -> delete the current user, then make a new user with the same user name OR different user name if you so desire for even better security and a new password for that user, and give them full permissions to the database when asked. Then edit your config.php entering the new username (if you made one) and the new password.

After doing this i am getting this error
Code:
Database Error  	Database error
The database has encountered a problem.
Please try the following:

    * Load the page again by clicking the Refresh button in your web browser.
    * Open the www.*******.com home page, then try to open another page.
    * Click the Back button to try another link.

The www.*********.com forum technical staff have been notified of the error, though you may contact them if the problem persists.
 
We apologise for any inconvenience.
 
They got in due to your weak file/folder permissions which you have already remedied. You should always keep your mods up to date and remove any you don't really need/use along with any associated template mods and files that were uploaded. Also keep an ear out for any vulnerabilities in any of the mods you have installed.
 
now i have changed the database username and password successfully. alot mods of files are in my public html dir which i uninstall them but i have no idea where are these files coz i forget :S
 
just check out the log that this server error has send you in your email address that you have specified in config.php, you can get a hint of this database error, might be the password and username in config.php doesnt match with your db username and pass....
 
After doing this i am getting this error

You do remember that cPanel uses your account name as a prefix for your database username, right? For instance, if your account is /home/vbteam/public_html and you choose the database username "joeblow" then your username becomes 'vbteam_joeblow' and that's what you need to put into your config.php.
 
Grinderhand said:
You do remember that cPanel uses your account name as a prefix for your database username, right? For instance, if your account is /home/vbteam/public_html and you choose the database username "joeblow" then your username becomes 'vbteam_joeblow' and that's what you need to put into your config.php.

yes i done a mistake i have not add the user to the database after adding it issue solved i also change the FTP and my cpanal password with a very very very very strong password :p
i have change all the file permission to 644 and the folder to 755
one thing left that is files of that mods which i have uninstalled :s
 
Sorry, I forgot that step. It's a lot of work after you get hacked, but it pays off in the end with a more secure site. You could try downloading the mods again (I assume you got them from here?) and looking into the archive for what files are installed where and go and remove them.
 
Grinderhand said:
Sorry, I forgot that step. It's a lot of work after you get hacked, but it pays off in the end with a more secure site. You could try downloading the mods again (I assume you got them from here?) and looking into the archive for what files are installed where and go and remove them.

Thanks soo much Bro you help me allot God Bless you n keep you always happy.
yes i make a list of all mods and i am going to download all of them and then i will sort out the files as you said .till that i make my Public_html password protected .
Thanks again Bro Be Happy
 
lol it is a shelll, most likely c99, remove it or rename it if you wanted to keep it, but i highly reccomend you remove it ASAP!
 
Back
Top