First you should remove the current phpmyadmin package:
rm -r /home/admispconfig/ispconfig/web/phpmyadmin
rm /home/admispconfig/ispconfig/web/phpmyadmin.tar.gz
rm -r /home/admispconfig/ispconfig/web/tools/tools/phpmyadmin
and install a new one trough ispconfig. Jonas is releasing new phpmyadmin packages for ispconfig on a regular basis, the latest package can be found here:
http://www.howtoforge.com/forums/showthread.php?t=47423
Then you will have to try to find the files that the hacker uploaded. If you know the creation date of the dc.txt, you can e.f. scan for files that date, especially interesiting are files inside /home/admispconfig/. Also look for files owned by the user admispconfig that are in unusual places (outside of /home/admispconfig). If you are unsure if a file belongs to ispconfig, feel free to post the path here.
You should then check your system with rkhunter and chkrootkit in case that the attacker was able to get root permissions.
Recent comments
1 day 4 hours ago
1 day 9 hours ago
1 day 14 hours ago
1 day 15 hours ago
2 days 6 hours ago
2 days 6 hours ago
2 days 11 hours ago
2 days 17 hours ago
2 days 18 hours ago
2 days 19 hours ago