• Resolved PL

    (@paris3)


    Last weekend, the WordFence Security plugin I use found a a possibly malicious file during a scan. The file mentioned the name of the theme I’m using, so I checked with the developer of that theme and they told me the file wasn’t their code.

    Then I contacted my hosting company to look into this and they told me my site wasn’t infected. Within an hour or so after this strange file appeared, I clicked the ‘delete file’ option on WordFence which messed up my theme.

    I was worried my site was hacked because it looked bare, but my host said it was just a theme issue and activated the default WordPress 2015. The hosting company told me how to do a malware scan with the Sucuri site. No issues appear in the scan and nothing else seems wrong with my site in appearance or in the dashboard. WordFence also shows no issues now.

    I’ve only been using WordPress for a year and never had anything like this happen before. Since I deleted this possibly malicious file, does that mean my site is okay? The infection type was listed as “Backdoor:PHP/array_map”, so could this still somehow affect my site or even my computer? I’m afraid to back up my site now and make things worse. I’ve posted a copy of the message that showed up in that Wordfence scan, but if anyone could give some input if there’s something else I should be doing about this issue or not.

    File appears to be malicious: wp-content/themes/wp_olsen5-v1.1.1/functions.php
    Filename: wp-content/themes/wp_olsen5-v1.1.1/functions.php
    File type: Not a core, theme or plugin file.
    Issue first detected: 9 mins ago.
    Severity: Critical
    Status New
    This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: “add_action(‘init’, create_function(”, implode(“\n”, array_map(“base64_decode”, unserialize(get_option”. The infection type is: Backdoor:PHP/array_map
    ———

Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Malicious file found, how to know if site it okay now?’ is closed to new replies.