my Login page is infected,
the footer of my site is infected
and the body text in the article too!
there could be more but I'm terribly frustrated in failing to clean this mess.
I deleted the wordpress files and copied a latest version in hope that it might clean the wp-login.php but it's still there! I can tell that this might have happened with the timthumb 0day exploit because of the theme that I was using "earthlytouch" that has a "timthumb.php" script.
The Anti-Malware quarantines the wp-login but it still appears after a few hours on the loginpage.
I want to know how deep this could be, like do I have to clean the whole database or can I clean it easily?
I'll be grateful if you could help me with this, thank you so much. Screenshots bellow,
EDITED: Added screenshots.