Title: pressdev1's Replies | WordPress.org

---

# pressdev1

  [  ](https://wordpress.org/support/users/pressdev1/)

 *   [Profile](https://wordpress.org/support/users/pressdev1/)
 *   [Topics Started](https://wordpress.org/support/users/pressdev1/topics/)
 *   [Replies Created](https://wordpress.org/support/users/pressdev1/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/pressdev1/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/pressdev1/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/pressdev1/engagements/)
 *   [Favorites](https://wordpress.org/support/users/pressdev1/favorites/)

 Search replies:

## Forum Replies Created

Viewing 1 replies (of 1 total)

 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Wordfence Security - Firewall, Malware Scan, and Login Security] Malware Scan ccode.php](https://wordpress.org/support/topic/malware-scan-ccode-php/)
 *  [pressdev1](https://wordpress.org/support/users/pressdev1/)
 * (@pressdev1)
 * [6 years, 1 month ago](https://wordpress.org/support/topic/malware-scan-ccode-php/#post-13121090)
 * One of my clients faced the same issue, they downloaded a theme from downloadfreethemes.
   co website. Following forensic examination, I found out that, ccode.php register
   itself as a plugin but hidden in the backend. It basically target add on traffic
   that is coming through search engines. It does not have access to SSH, SFTP or
   create uses or steal user/admin credentials.
 * To mitigate, let the Wordfence plugin scan outside of the WordPress directory
   and you will need to carry a sensitive full scan and delete the offending files
   or the lines of code suggested by Wordfence plugin.

Viewing 1 replies (of 1 total)