See: https://www.virustotal.com/nl/url/6fc058fb3e31f421141d35e5640a27b1711dc607393b2262985e354c5891069f/analysis/1385302442/
and file analysis: https://www.virustotal.com/nl/file/232c735497c29a4583a577c8b6f5bbc2d9e3e06d3e42f9799aa1f7a7e9de7afc/analysis/1385241935/
Not detected or alerted here: http://urlquery.net/report.php?id=7933400
Blacklisted: http://trafficlight.bitdefender.com/info?url=http://gesundheitscentrum-frechen.de
Other malware on IP: http://support.clean-mx.de/clean-mx/viruses?id=15458828
Joomla error flagged: >jos-Error: Kategorie nicht gefunden
JSite → dispatch() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/index.php:42
JComponentHelper :: renderComponent() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/includes/application.php:197
JComponentHelper :: executeComponent() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/libraries/joomla/application/component/helper.php:351
require_once() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/libraries/joomla/application/component/helper.php:383
JController → execute() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/components/com_content/content.php:16
ContentController → display() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/libraries/joomla/application/component/controller.php:761
JController → display() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/components/com_content/controller.php:74
ContentViewCategory → display() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/libraries/joomla/application/component/controller.php:722
JError :: raiseError() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/components/com_content/views/category/view.html.php:59
JError :: raise() @ /is/htdocs/wp10928300_M9X6JJXGYK/wXw/ghz/libraries/joomla/error/error.php:251
This is a MySQL Query Syntax Error after admin login (info credits: Lukasz Jaroszewski) - server error → setting(unset after installation):
probably because of Trojan.PHP.Agent.GA - It sends details on the URL requested, remote IP address, browser user-agent, etc to “http://mbrowserstats.com/statH/stat.php”. Is flagged by several av solutions, but can it be legit or is it a PHPShell-backdoor?
see: htxp://hackw0rm.blogspot.nl/2013/06/C99Shell-backdoor.html
polonus