Unfortunately earlier this evening it would seem that our account (scriptinstallation.ca) was hacked. The person or persons who did the hacking may have had access to our whmcs support tickets and orders so if you have provided us with FTP access details in the past PLEASE CHANGE THESE...
I decided to write this little guide on destroying a nice ring3 rootkit, or at-least removing the most of it...
BetaBot is malware created by someone named BetaMonkey on hackforums, well it is a nice rootkit malware, with a snazzy http panel, it's easy to kill.
Login to your computer like...
Any russian providers?
I picked up a server in Romania, NL, just looking for Russia now (dedicated servers).
I also tried a VPS in iceland, it's actually very good.
If you're scared, why not go get a prepaid visa, load it with the amount needed and use that? Pretty simple solution and due to the fact they are offshore, I doubt they have any anti-fraud modules in place, so you don't needa use real name, etc.
Ogawd.
What the fuck did I just read....
https://github.com/BlueVM/Feathur/blob/develop/feathur/admin.php
Oh my god. You're serious, right?
https://github.com/BlueVM/Feathur/blob/develop/feathur/admin/createvps.php
Points:
1) Why are you using a shitty loader?
2) Why not use PHP's default...