Sajesh Mohan Posted March 8, 2012 Share Posted March 8, 2012 wordpress and we keep getting malware in the php files.affected with EVAL & Base64 malware how can i solve the issue. Quote Link to comment https://forums.phpfreaks.com/topic/258523-wordpress-site-infected-with-malware/ Share on other sites More sharing options...
nicsnow Posted March 10, 2012 Share Posted March 10, 2012 check out ftp server and look for the latest modified file. If it looks dodgy delete it. Then shore up your patches/server protection. Look at the htaccess file Quote Link to comment https://forums.phpfreaks.com/topic/258523-wordpress-site-infected-with-malware/#findComment-1325833 Share on other sites More sharing options...
erinpurdy Posted March 30, 2012 Share Posted March 30, 2012 My friend had the same problem but he modified and backup the files before he did the process.. I'll ask him again the whole details what he did to fix the virus and I'll keep you posted. Quote Link to comment https://forums.phpfreaks.com/topic/258523-wordpress-site-infected-with-malware/#findComment-1332562 Share on other sites More sharing options...
TimeBomb Posted April 1, 2012 Share Posted April 1, 2012 I've actually been dealing with a few clients of mine who have recently had their Wordpress sites injected with malware. I dealt with 3 different websites. Two of them were very similar. A plugin and file in the wp_uploads folder allowed for easy code injection. Code was injected into a few index.php files. I manually removed the code, double and triple checked every single file for any sort of possible issue. I searched for the keywords eval, base64, and <script. All keywords that aren't heavily used throughout Wordpress, but are quite common to website injections. After finding nothing, I went into the wordpress admin panel, made sure there were no 'ghost' users, as some malicious bots will set themselves up as administrator as to easily reinfect your website. I updated wordpress and every single plugin. I changed the wordpress password. Because these types of viruses can also infect websites through a user accessing the website's admin panel, FTP, etc, I told my clients to scan for viruses and malware in any and all computers which they may use to access these backend interfaces. The third one was a lot worse. Every single PHP file was infected. I backed up what I could - including uploaded images (making sure there were no PHP files and no malicious files in the folders), and the database. I took note of all the installed themes and plugins, and then proceeded to delete every single file on their FTP. It was that badly infected. I cleanly installed Wordpress. This entire process was made easier because she had been using the latest version of Wordpress. I restored her database, changed her wordpress admin password, as well as FTP password, and told her to completely scan all her computers, as I did my previous clients. I made sure I installed the latest version of all the plugins that she was using, and I also restored her themes. The malware has not returned. Quote Link to comment https://forums.phpfreaks.com/topic/258523-wordpress-site-infected-with-malware/#findComment-1333250 Share on other sites More sharing options...
trafacs Posted April 7, 2012 Share Posted April 7, 2012 Hi Dude, Look at the htaccess file, Than check your last updated file/folder. if you find any extra file's there, check properly and remove if not supporting to you. may be it will be solved. Quote Link to comment https://forums.phpfreaks.com/topic/258523-wordpress-site-infected-with-malware/#findComment-1335141 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.