I have removed the malware code from functions.php in all my installations along with wp-tmp and wp-vcd files but the malware reapears. There must be hiding elsewere too. Even on a local install and having functions.php read only. The malware managed to add the code inside again. Any thoughts?