Title: Alleged malicious code
Last modified: August 22, 2016

---

# Alleged malicious code

 *  Resolved [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/)
 * Got this a few days ago from my host:
 * This notice is to inform you that we have detected malicious code in your website
   files. We have compiled a list of compromised files on your account, as well 
   as the code injected, below.
 * In order to maintain a secure hosting environment, we will be automatically correcting
   these compromised files on your account; however, please be aware that you are
   responsible for verifying that the content hosted within your account is secure.
   We strongly advise that you update your installed scripts and software, as outdated
   scripts and software are the most frequently used method for accessing and gaining
   control of a targeted account.
 * If you need assistance updating the software on your hosting account, please 
   do not hesitate to contact our Support department.
 * The compromised files detected are:
 * /home4/mademer1/public_html/globalindieauthor/wp-includes/js/tinymce/utils/ossdl-
   cdn.php
 * The malicious code detected is similar to:
 * Files with the following contents or MD5SUMs, which contain malicious code:
    \
   $default_action\s*=\s*[‘”]FilesMan[‘”]\s*
 * When I check the directory, the ossdl-cdn.php is absent. So I cannot tell if 
   my host removed it because “we will be automatically correcting these compromised
   files on your account” or because the files are hidden.
 * I have looked this up and there are several examples of the same warning from
   one’s host provider but each time the alleged offending file is different.
 * Any ideas as to how I can verify and remove this code?
 * Thanks.

Viewing 15 replies - 1 through 15 (of 36 total)

1 [2](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
[3](https://wordpress.org/support/topic/alleged-malicious-code/page/3/?output_format=md)
[→](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)

 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757005)
 * Hm, that seems odd, we have not heard of any such vulnerabilities in that file,
   so either the host is wrong, or the file was modified. It’s probably safest to
   replace all of the core files.
 * Try [downloading WordPress](https://wordpress.org/download/) again and delete
   then replace your copies of everything **except** the `wp-config.php` file and
   the `/wp-content/` directory with fresh copies from the download. This will effectively
   replace all of your core files without damaging your content and settings. Some
   uploaders tend to be unreliable when overwriting files, so don’t forget to delete
   the original files before replacing them.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757038)
 * Hi James,
 * I’m not a programmer, so please bear with me. I installed WP originally via my
   site host, Just Host. I have three WP sites attached to my main website, which
   is not WP. The allegedly infected site is [http://www.mademers.com/globalindieauthor](http://www.mademers.com/globalindieauthor).
 * In my file manager on Just Host, when I look in the folder globalindieauthor,
   I can see the wp-config.php in the root directory, and I can see the subfolder
   wp-content. Are you saying I should delete the wp-includes and wp-admin folders,
   as well as all files in the root except for the wp-config.php?
 * If so, when I download WP again through Just Host, will it not simply create 
   yet another WP site? Do I have to do this through FTP instead?
 * Thanks.
 * P.S. It gets weirder. Just Host told me to check my site at sucuri.net. When 
   I did, nothing in WP came up as infected. But two others did:
 * > [http://mademers.com/404testpage4525d2fdc](http://mademers.com/404testpage4525d2fdc)
   > [http://mademers.com/404javascript.js](http://mademers.com/404javascript.js)
   > malware-entry-mwhjck3123?se1
   > Malware entry: MW:HJCK:3123
   > A hidden and suspicious javascript (or iframe) was found on the site. It is
   > loaded from a blacklisted (and malicious domain) and used to steal information
   > from site visitors and/or infect them. Loads malware from multiple locations:
   > [http://dsnextgen.com/?a_id=10636](http://dsnextgen.com/?a_id=10636)..
   >  [http://perfumefrosty.org/nnc0xazxwahh5ifg/](http://perfumefrosty.org/nnc0xazxwahh5ifg/)
   > [http://www.paid-to-promote.net/](http://www.paid-to-promote.net/) [http://www.777seo.com/pop.php?username=](http://www.777seo.com/pop.php?username=)..(
   > and many other domains).</p>
   > This malware is generally hidden on .js or .php files without heavy encoding.
 * And of course to clean the site costs $99.00 I’m beginning to think I’m being
   had.
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757042)
 * > Are you saying I should delete the wp-includes and wp-admin folders, as well
   > as all files in the root except for the wp-config.php?
 * Yes.
 * > If so, when I download WP again through Just Host, will it not simply create
   > yet another WP site?
 * No, as mentioned, you will download WordPress from [https://wordpress.org/download/](https://wordpress.org/download/)
   and upload the files via FTP.
 * Sucuri is very trustworthy, so if they say you’ve been infected, it’s pretty 
   definite you have.
 * Given when you just mentioned above, I’d suspect that something has opened a 
   backdoor in your hosting account and is infecting other files.
 * When you’re done, you may want to implement some (if not all) of [the recommended security measures](https://codex.wordpress.org/Hardening_WordPress),
   though that won’t protect the non-WordPress things.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757052)
 * Thanks, James. Will do as directed.
 * The weird thing about the sucuri result is that I have never been notified of
   any infections on my main site (which gets only a fraction of the visits that
   my globalindieauthor site gets) from either my host or Google. And, as indicated,
   sucuri found nothing wrong with WP but Just Host did, while Just Host found malicious
   files on WP but nothing on my main site. How is one supposed to respond to that?
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757057)
 * > The weird thing about the sucuri result is that I have never been notified 
   > of any infections on my main site (which gets only a fraction of the visits
   > that my globalindieauthor site gets) from either my host or Google.
 * It’s not really your host’s job or Google’s job to notify you about malware, 
   I just think your host is watching all of their WordPress installations more 
   closely.
 * > And, as indicated, sucuri found nothing wrong with WP but Just Host did, while
   > Just Host found malicious files on WP but nothing on my main site.
 * Sucuri can only scan what it seems publicly. The file your host found would only
   be used in the Dashboard. Your host has access to all of your files, which is
   why they found it.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757059)
 * I see.
 * I’ve been told that WP is having problems with malware-infected plugins. Is this
   why my host would be watching WP sites more closely?
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757062)
 * Probably, there have been a few plugins recently which weren’t coded too securely
   and were then exploited.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757063)
 * Thanks for your help, James. I appreciate it.
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757064)
 * You’re welcome!
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757091)
 * Hi James,
 * Went online this evening to execute said upload only to notice several files 
   in my current WP directories that do not exist in the downloaded ZIP file. My
   suspicion is that these are related to the theme I am using. I suspect havoc 
   will ensue if I delete these files. Then again, they could be malicious files;
   I wouldn’t know. Specifically, these are the files that are in my WP directory
   that do not exist in the ZIP file:
 * root directory (/home4/mademer1/public_html/globalindieauthor):
    fantversion.
   php wp-atom.php wp-commentsrss2.php wp-feed.php wp-pass.php wp-rdf.php wp-register.
   php wp-rss.php wp-rss2.php wp-xmlrpc.php
 * wp-admin:
    ajax-upload.php
 * wp-admin/includes:
    install.php options-reading.php
 * wp-admin/js:
    default_folder.php
 * wp-admin/network:
    details_up.php
 * wp-includes:
    class-wp-smtp-bar.php class.wp-dependencies.php class.wp-scripts.
   php class.wp-styles.php
 * wp-includes/certificates:
    patfactory.php tdomf-upload-functions.php
 * wp-includes/css:
    mod_search.php themes.php
 * wp-includes/js/crop:
    default_ftp.php
 * wp-includes/js/jquery/ui:
    jquery.ui.accordion.min.js jquery.ui.autocomplete.
   min.js jquery.ui.button.min.js jquery.ui.core.min.js jquery.ui.datepicker.min.
   js jquery.ui.dialog.min.js jquery.ui.draggable.min.js jquery.ui.droppable.min.
   js jquery.ui.effect-blind.min.js jquery.ui.effect-bounce.min.js jquery.ui.effect-
   clip.min.js jquery.ui.effect-drop.min.js jquery.ui.effect-explode.min.js jquery.
   ui.effect-fade.min.js jquery.ui.effect-fold.min.js jquery.ui.effect-highlight.
   min.js jquery.ui.effect-pulsate.min.js jquery.ui.effect-scale.min.js jquery.ui.
   effect-shake.min.js jquery.ui.effect-slide.min.js jquery.ui.effect-transfer.min.
   js jquery.ui.effect.min.js jquery.ui.menu.min.js jquery.ui.mouse.min.js jquery.
   ui.position.min.js jquery.ui.progressbar.min.js jquery.ui.resizable.min.js jquery.
   ui.selectable.min.js jquery.ui.slider.min.js jquery.ui.sortable.min.js jquery.
   ui.spinner.min.js jquery.ui.tabs.min.js jquery.ui.tooltip.min.js jquery.ui.widget.
   min.js
 * wp-includes/js/tinymce/langs:
    wp-langs-en.phtml
 * wp-includes/js/tinymce/plugins/colorpicker:
    strspn.php
 * wp-includes/js/tinymce/plugins/compat3x/css:
    folder.php
 * wp-includes/js/tinymce/plugins/fullscreen:
    pdf.php
 * wp-includes/js/tinymce/plugins/tabfocus:
    zip.php
 * wp-includes/js/tinymce/plugins/wpeditimage:
    defines.php
 * wp-includes/js/tinymce/plugins/fullscreen:
    DB.php
 * wp-includes/js/tinymce/plugins/wpgallery:
    BBCode.php
 * wp-includes/js/tinymce/plugins/wplink:
    frontpage.php
 * wp-includes/js/tinymce/plugins/wpview:
    move.php
 * wp-includes/js/tinymce/skins/lightgray/fonts:
    tdomf-subscribe-to-comments-widget.
   php
 * wp-includes/js/tinymce/skins/wordpress:
    directory.php
 * wp-includes/js/tinymce/skins/wordpress/images:
    dashicon-no-alt.png
 * wp-includes/SimplePie:
    index.php
 * wp-includes/SimplePie/Content/Type:
    nav-menu.php
 * wp-includes/SimplePie/HTTP:
    InputFilter.php
 * wp-includes/SimplePie/XML/Declaration:
    details_img.php ms-users.php
 * wp-includes/Text/Diff:
    admin.languages.html.php
 * wp-includes/Text/Diff/Engine:
    xml_domit_xpath.php
 * wp-includes/Text/Diff/Renderer:
    freesansbi.php
 * wp-includes/theme-compat:
    string.php
 * As you can see, there are dozens. Should I leave them in or remove them?
 * Thanks.
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757102)
 * Those should all be in the download. Did you get the download from [https://wordpress.org/download/](https://wordpress.org/download/)?
 * It’s a .zip file, which you’ll expand, and it will then have all of those files.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757113)
 * I downloaded the archive (WordPress-4.1.zip) from the link you provided. When
   I compared the contents to what was in my WP folders on my website, the files
   I listed were on my website server but not in the zip file. I double-checked;
   if you unzip the archive and look in wp-includes/js/jquery/ui, for example, none
   of the jquery.ui files listed above are in there.
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757116)
 * Hm, you’re right, sorry about that. Your theme shouldn’t be messing with core
   files anyway, so those were probably added by whatever black door was exploited.
 * Go ahead and remove and replace the enter wp-includes and wp-admin directories,
   as well as the root-level core files, except wp-config.php and the wp-content
   directory.
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757227)
 * Hi James,
 * I did as directed and now my WP site does not work: [http://www.mademers.com/globalindieauthor](http://www.mademers.com/globalindieauthor).
   At first glance it appears normal, but if one clicks on a blog post to read it,
   they get a 404 error. All my header links to my pages return 404 errors.
 * I can log in and everything is still there: the posts, the comments, the pages,
   but the links have been broken somehow.
 * Now what?
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/#post-5757228)
 * Try re-saving your permalink structure at Settings/Permalinks in your admin panel.
   If WordPress cannot automatically edit the `.htaccess` file, it will provide 
   manual instructions after saving.

Viewing 15 replies - 1 through 15 (of 36 total)

1 [2](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
[3](https://wordpress.org/support/topic/alleged-malicious-code/page/3/?output_format=md)
[→](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)

The topic ‘Alleged malicious code’ is closed to new replies.

## Tags

 * [remove](https://wordpress.org/support/topic-tag/remove/)

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 36 replies
 * 5 participants
 * Last reply from: [stbedesantafe](https://wordpress.org/support/users/stbedesantafe/)
 * Last activity: [11 years, 4 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757366)
 * Status: resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
