It can be really hard to detect changes on a well hacked server, you really need to check everything twice or three times as you move it all to a fresh machine. If it is server based, you could never trust that installation again.
I assume you have run all the rootkit checkers etc on the system for clues ?
|