Title: catt.php, malware?
Last modified: March 6, 2018

---

# catt.php, malware?

 *  Resolved [Charles Sandor](https://wordpress.org/support/users/charles-sandor/)
 * (@charles-sandor)
 * [8 years, 2 months ago](https://wordpress.org/support/topic/catt-php-malware/)
 * I just got this message from GoDaddy today. Our website is hosted by GoDaddy 
   and we are using WooCommerce on the site. This is the message:
 * We recently completed a routine security checkup of our servers and platforms.
   Our scans flagged your aowilson.ca hosting accounts as containing possible malware.
 * Please sign in to your hosting account and review the following content and remove
   or fix the files listed below:
    php.malware.fopo_obfuscator.001 – html/catt.php
 * I ran a check on the site with Sucuri and Virus Total and both checks found no
   malware issues.
 * There is a file on the site called catt.php
 * Is this a malware file or is it tied to the e-commerce on the website. Want to
   know if I should delete this file and hope it won’t imapct the ecommerce
 * The page I need help with: _[[log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fcatt-php-malware%2F%3Foutput_format%3Dmd&locale=en_US)
   to see the link]_

Viewing 2 replies - 1 through 2 (of 2 total)

 *  [Caleb Burks](https://wordpress.org/support/users/icaleb/)
 * (@icaleb)
 * Automattic Happiness Engineer
 * [8 years, 2 months ago](https://wordpress.org/support/topic/catt-php-malware/#post-10046598)
 * Hello,
 * Where is the file located exactly? It does look suspicious. There is no file 
   by that name in the WooCommerce plugin. It’s probably in your website root, which
   means you sever was compromised.
 * So I recommend removing that file, and changing all passwords. WordPress admin
   accounts, FTP accounts, Database account, and updating wp-config.php with the
   new passwords for the database user.
 * More info: [https://codex.wordpress.org/FAQ_My_site_was_hacked](https://codex.wordpress.org/FAQ_My_site_was_hacked)
    -  This reply was modified 8 years, 2 months ago by [Caleb Burks](https://wordpress.org/support/users/icaleb/).
 *  Plugin Support [Shaun Kuschel a11n](https://wordpress.org/support/users/shaunkuschel/)
 * (@shaunkuschel)
 * Automattic Happiness Engineer
 * [8 years, 2 months ago](https://wordpress.org/support/topic/catt-php-malware/#post-10071346)
 * Since we haven’t heard anything in a while, we’re going to go ahead and mark 
   this thread as resolved. However, if you are still experiencing issues, let us
   know by opening a new thread (and feel free to link to this one).

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘catt.php, malware?’ is closed to new replies.

 * ![](https://ps.w.org/woocommerce/assets/icon.svg?rev=3234504)
 * [WooCommerce](https://wordpress.org/plugins/woocommerce/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woocommerce/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woocommerce/)
 * [Active Topics](https://wordpress.org/support/plugin/woocommerce/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woocommerce/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woocommerce/reviews/)

 * 2 replies
 * 3 participants
 * Last reply from: [Shaun Kuschel a11n](https://wordpress.org/support/users/shaunkuschel/)
 * Last activity: [8 years, 2 months ago](https://wordpress.org/support/topic/catt-php-malware/#post-10071346)
 * Status: resolved