It seems it is the theme, how do I go about finding the malicious code and removing it? Anything to look out for? What file would it be in?
Sorry, I'm a complete noob.
exploit scanner found this
wp-content/themes/thesis_182/lib/scripts/jscolor/jscolor.js:78
Often used to execute malicious code eval('prop='+m[3])
wp-content/plugins/pretty-link/includes/jquery/js/jquery-1.3.2.min.js:12
Often used to execute malicious code .src,async:false,dataType:"script"})}else{o.globalEval(F.text||F.textContent||F.innerHTML||"")}if(F.pa
wp-content/plugins/pretty-link/includes/jquery/js/jquery-1.3.2.min.js:19
Often used to execute malicious code )}if(typeof I==="string"){if(H=="script"){o.globalEval(I)}if(H=="json"){I=l["eval"]("("+I+")")}}return
wp-content/plugins/pretty-link/includes/jquery/js/jquery-ui-1.7.1.custom.min.js:122
Often used to execute malicious code s=inlineSettings||{};try{inlineSettings[attrName]=eval(attrValue)}catch(err){inlineSettings[attrName]=
wp-content/plugins/pretty-link/includes/version-2-kvasir/js/json/json2.js:444
Often used to execute malicious code j = eval('(' + text + ')');
wp-content/plugins/exitsplash/files/lightbox/jquery.lightbox.min.js:17
Often used to execute malicious code eval(function(p,a,c,k,e,r){e=function(c){return(c<a?
wp-content/plugins/exitsplash/files/jquery-1.5.2.min.js:16
Often used to execute malicious code x({url:b.src,async:!1,dataType:"script"}):d.globalEval(b.text||b.textContent||b.innerHTML||""),b.parentNode&&b.parentNode.removeChild(b)}functi [line truncated]
wp-content/plugins/exitsplash/colorpicker/js/jquery.js:552
Often used to execute malicious code jQuery.globalEval( elem.text || elem.textContent || elem.innerHTM
wp-content/plugins/exitsplash/colorpicker/js/jquery.js:3721
Often used to execute malicious code jQuery.globalEval( data );
Eval( was highlited. Both are "nulled" things that I downloaded