Hacked - where is this index.php

Hacked - where is this index.php

by Albert Dudley -
Number of replies: 3
Hi,
It seems that I have been hacked (moodle 1.8.3). Art Lader provided me with recovery link http://docs.moodle.org/en/Hacked_site_recovery.
However, I am but a instructional designer and not an IT. When I go to my front page of my moodle I see the following (see below): Where is this file located? I would like to take that code out of there. I have looked everywhere and cannot find it.
- I am going through my cpanel in file manager. It is not in admin index.php etc.. I will upgrade to 1.9.5 once I have done this( if I can). Does anyone outthere do this for a living. I mean disinfect sites?
This is what I want to get rid of: (thanks for your support)

//]]>
</script>
</head>

<body class="admin course-1 lang-en_utf8" id="admin-maintenance"><i style="display:none">
xeex322705
<a href=http://art.gprc.ab.ca/moodle/query.php?str=cialis>cialis</a>
<a href=http://art.gprc.ab.ca/moodle/query.php?str=buy+cialis>buy cialis</a>
<a href=http://art.gprc.ab.ca/moodle/query.php?str=generic+cialis>generic cialis</a>
<a href=http://art.gprc.ab.ca/moodle/query.php?str=cialis+online>cialis online</a>
<a href=http://art.gprc.ab.ca/moodle/query.php?str=cialis+generic+viagra>cialis generic viagra</a>
Average of ratings: -
In reply to Albert Dudley

Re: Hacked - where is this index.php

by Mary Cooch -
Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Testers Picture of Translators
Try config.php
Average of ratings: Useful (2)
In reply to Mary Cooch

Re: Hacked - where is this index.php

by Albert Dudley -
Hi Mary,

Thank you once again for the support. You were right. In fact, the file consisted of mainly (90%) of this code.
What a drag!
thank you

Albert
In reply to Albert Dudley

Re: Hacked - where is this index.php

by Mary Cooch -
Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Testers Picture of Translators
Do look elsewhere as well though - check the modification dates on your server -that is usually a clue if they are all around the same time same day. And then upgrade!