Quote:
Originally Posted by ryancooper
@Kylek thanks for the info in PM Lookign now but so far no luck
@ZomgStuff - What did you look for in the .js files?
Thanks for any help!
|
If you have a custom mod like a chatbox or any custom mods simply replace all the .js files of that mod w/ a fresh downloaded copy.
AdminCP > Maintenance > Diagnostics > Suspect File Versions
*Now, not all files are "suspect" or "bad" but that will help you track down the files if you are unaware of them all. Be sure to check your .js files as mentioned above and also check your templates for any iframes so search in templates for
Code:
<IFRAME SRC="whatever.html"
Leave the part after the = off so you can find all instances, some of these malicious scripts utilize iframes, there is a currently popular iframe and js baddy for Word Press atm so if you have that installed this could be the aftermath if they hacked your site via an exploit.