PRICING SUPPORT LOGIN

This script can be found on doorway pages created by hackers. It creates a full window size iframe that loads a third party site (e.g. some e-commerce site that spammers promote). On some sites, this script can be in standalone .js files, included by .html doorway files.
Variant of iframe-doorways.

Affecting

Any type of site.

Cleanup

You should remove the doorway files and .js files with the malicious code. Usually there is also some infected PHP files that make doorways work differently for bots and human visitors. You can contact Sucuri to help you with the infection removal.

Dump

var _$=["\x3C\x64\x69\x76\x20\x73\x74\x79\x6C\x65\x3D\x27\x7...this part may vary... \x3E\x3C\x2F\x64\x69\x76\x3E"];document.writeln(_$[0]);