tj2419 Posted November 2, 2015 Posted November 2, 2015 I'm trying to access one of our moodle courses and it is coming up in chrome saying it is infected. Each time I try access it I just get redirected to an external wordsearch site wordsearchmaker.net :S Infection Type: JS:ScriptIP-inf [Trj] Anyone know how I can access the course? Thanks
3s-gtech Posted November 2, 2015 Posted November 2, 2015 You'll need to delve into your Moodle files and database. Something has either been popped into your database (more likely) or into the Moodle files themselves. Do you have backups? Either Phpmyadmin or HeidiSQL will be handy here. Ours was hacked many years back, due to old insecure versions of LAMP, so if you find it it's worth looking at updating everything afterwards.
tj2419 Posted November 3, 2015 Author Posted November 3, 2015 In a weird twist students are able to access the course fine. Teachers and admins cannot. I have searched in the database for Thanks
3s-gtech Posted November 3, 2015 Posted November 3, 2015 The course ID and anything associated with that entry would be the first thing to look for. It's possible that rather than the course having been altered, that the admin pages have been changed. If you don't have much luck, make a full backup of the site including database, do an update/reinstall, then test again. Your moodledata folder shouldn't need to be touched though, at this stage.
bencellis Posted November 3, 2015 Posted November 3, 2015 It would appear that it is the PCs that are infected. A Google search brings up quite a few links on how to remove the Javascript virus - https://www.google.co.uk/search?q=Infection+Type%3A+JS%3AScriptIP-inf+[Trj]
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now