Hacked WordPress Blog – need help
-
This is my second topic issue but it may be related to the first.
Yesterday I started to receive loads of “New User Registration” posts – about six per hour. I cleaned out the old New User Registration” posts and installed two pluggins – Akismet and Bad Behavior – to try to stop the SPAM.
I am still getting six hits per hour.
Today I have made a backup of my blog on my desktop and I contacted my web server support. While on hold I started opening files.
One folder is called “wp-3e30af” – is this a normal folder within WordPress?
It contains a jquery.menu.js file that looks a little funny to me. . .
Here are some excepts of the code – does this look like JQuery code to you?
getScript|http|fanandish|com|tmp|js’.split
or var|dom|http|i|net2route|com|format|width|618|height|124|imgstyle|back1|kq1|Adult|Dating’.split(‘|’)
or
a href=”https://lookforweboffer.com/ifeed/link/1000//Dating+services/1″ target=”_blank”I am no expert but I don’t think that this is normal JQuery code.
I believe that I have been hacked.
The http|fanandish|com website is in Iran. Holy Crap. Does anyone read Farsi?
So I need to know how to clean this up.Anyone know where to read up on this type of attack so that I can find all of the corruption and delete it?
My plan right now is to download a clean copy of WordPress and start replacing files. Do you think that this is a good idea?
A friend suggested that the hacker may also have code in my database – is that true?
I am playing “Beat the Clock” on this. New SPAM is being reported in my email like the sands of time running out. Please help!
- The topic ‘Hacked WordPress Blog – need help’ is closed to new replies.