Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

URL Injection into our Wordpress Website - How do I remove it?

Posted on 2016-11-08
7
Medium Priority
?
764 Views
Last Modified: 2016-11-09
Over a week ago we were told that our website is listed on Google as being hacked. I see that lots of WP sites have been getting hacked/injected with Malware. Google scan shows the exact lines of code that was injected into our site. Security plugins and SiteLock site scans have been deployed and has cleaned up most of the malware and I have changed all of the passwords. My question is... how do I go about manually removing the remaining code. I'm not in any way a website person, I've looked around different folders/files within the site but I've failed to locate the web links as shown by Google crawl security issues. Our site is up and running and no visible damage has been done. But a Google search shows a bunch of Japanese characters in the title bar. If you can help me or need more information so that you can help me I'm ready to provide it. Thank you all in advance.
DIRTECH-Godaddy-Website-HTTP-Code.docx
0
Comment
Question by:LemonCalvin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 30

Expert Comment

by:Thomas Zucker-Scharff
ID: 41878849
theme configuration file.
0
 

Author Comment

by:LemonCalvin
ID: 41878971
The Themes folder didn't contain any config files specifically but I did take a look at the index and header files but no links were in either of them. Where can I find the Theme Configuration File? Perhaps i'm looking in the wrong folder. Thanks.
0
 

Author Comment

by:LemonCalvin
ID: 41879094
I got this list of modified files from via a plugin on the website. Now I have to figure out how to safely edit/remove them so I dont crash our site.
Website-Modified-Files-11-8-16.png
0
Plesk WordPress Toolkit

Plesk's WordPress Toolkit allows server administrators, resellers and customers to manage their WordPress instances, enabling a variety of development workflows for WordPress admins of all skill levels, from beginners to pros.

See why 2/3 of Plesk servers use it.

 
LVL 30

Expert Comment

by:Thomas Zucker-Scharff
ID: 41879149
What are you using to access the site (direct/FTP/Plugin)?  Config files do not end in cfg they are php fiiles.
0
 
LVL 30

Accepted Solution

by:
Thomas Zucker-Scharff earned 2000 total points
ID: 41879157
Depending on how conversant you are with WordPress, you might consider the FileManager plugin.  If you have direct access, something like VI or notepad++, or filezilla for FTP access.
0
 

Author Comment

by:LemonCalvin
ID: 41879282
Hi - I'm using Filezilla ftp client to access the files.
0
 

Author Closing Comment

by:LemonCalvin
ID: 41880376
Hired someone to clean and manage website. Thanks for your help.
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An introduction to the wonderful sport of Scam Baiting.  Learn how to help fight scammers by beating them at their own game. This great pass time helps the world, while providing an endless source of entertainment. Enjoy!
IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question