Quote from: mmcgee at Jul 22, 2014, 12:55 AMIn my assets directory there is:
.cache.idx.php
cache.php
xPDO.idx.php
Are all 3 of these bad?
I don't have any .php files in the assets folder of my 2.2.13 install. I don't have a 2.3 install to look at, but I think they're suspect.
Take a look at the contents for any lines that contain @eval or base64_decode.
The base64_decode lines will contain something like this:
$v = base64_decode('alkjlkjelkjsaslkjaslkjljasd ... ');
About your non-MODX sites: they're probably safe, but I would at least change the usernames and passwords and look around for any suspicious .php files or suspicious users.