My server was hacked because i have VBET.
THIS IS THE CLUE THAT CONFIRMS IT:
I CAN´T UNINSTALL VBET!!root 27888 1 0 18:26 ? Ss 0:00 /usr/sbin/exim -Mc 1OSBjj-0007Cf-4S SERVER_SIGNATURE=<address>Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www****com Port 80</address>? UNIQUE_ID=TCTYtbylwV0AAEFiMjYAAABQ HTTP_USER_AGENT=Wget/1.10.2 (Red Hat modified) SERVER_PORT=80 HTTP_HOST=www****com DOCUMENT_ROOT=/home/w11s0s3r/public_html SCRIPT_FILENAME=/home/w11s0s3r/public_html/vbenterprisetranslator_seo.php REQUEST_URI=/archive/index.php/f-23.html SCRIPT_NAME=/vbenterprisetranslator_seo.php HTTP_CONNECTION=Keep-Alive REMOTE_PORT=41741 PATH=/bin:/usr/bin PWD=/home/w11s0s3r/public_html SERVER_ADMIN=webmaster****com REDIRECT_UNIQUE_ID=TCTYtbylwV0AAEFiMjYAAABQ REDIRECT_STATUS=200 HTTP_ACCEPT=*/* REMOTE_ADDR=72.55.191.104 SHLVL=1 SERVER_NAME=www***com HTTP_PRAGMA=no-cache SERVER_SOFTWARE=Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 QUERY_STRING= SERVER_ADDR=188.165.193.93 GATEWAY_INTERFACE=CGI/1.1 SERVER_PROTOCOL=HTTP/1.0 REDIRECT_URL=/archive/index.php/f-23.html REQUEST_METHOD=HEAD _=/usr/sbin/sendmail
w11s0s3r 27996 27888 1 18:26 ? D 0:00 /usr/sbin/exim -Mc 1OSBjj-0007Cf-4S SERVER_SIGNATURE=<address>Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www***com Port 80</address>? UNIQUE_ID=TCTYtbylwV0AAEFiMjYAAABQ HTTP_USER_AGENT=Wget/1.10.2 (Red Hat modified) SERVER_PORT=80 HTTP_HOST=www****com DOCUMENT_ROOT=/home/w11s0s3r/public_html SCRIPT_FILENAME=/home/w11s0s3r/public_html/vbenterprisetranslato^C
Please help me my server is sending a lot of SPAM e-mails!
Is being cracked!
HELP Michał Podbielski!