Jump to content


Photo
- - - - -

Removing malicious content in wordpress editor.Please help


  • Please log in to reply
1 reply to this topic

#1 cillablay

cillablay

    Member

  • Members
  • 23 posts
  • Country: Country Flag

Posted 26 October 2013 - 06:02 AM

Hi

 

Last year around christmas, my website was hacked and it has happened this year too. I have looked in the header.php file in wordpress editor and realised there are texts on there which compromise my website. Can you please let me know if it is ok to go ahead and delete that piece of code from the header file to get rid of the text? will that affect my pagelines updates and website in general. I am asking because on the editor page, there is a warning not to edit the files in the folder but I am not sure how else to remove the code since it seems to be from december last year

 

Please please help me. below is the code for my header

 

<?php
/**
 * HEADER
 *
 * This file controls the HTML <head> and top graphical markup (including
 * Navigation) for each page in your theme. You can control what shows up where
 * using WordPress and PageLines PHP conditionals.
 *
 * @package     PageLines Framework
 * @since       1.0
 *
 * @link       

Please Login or Register to see this Hidden Content


 * @link       

Please Login or Register to see this Hidden Content


 *
 * @author      PageLines  

Please Login or Register to see this Hidden Content


 * @copyright   Copyright © 2008-2012, PageLines  hello@pagelines.com
 *
 * @internal    last revised January 23, 2012
 * @version     ...
 *
 * @todo Define version
 */

pagelines_register_hook('pagelines_before_html'); // Hook
?><!DOCTYPE html>
<html <?php language_attributes(); ?>>
<head>
<?php
        pagelines_register_hook('pagelines_head'); // Hook

        wp_head(); // Hook (WordPress)

        pagelines_register_hook('pagelines_head_last'); // Hook ?>

</head>
<?php

echo pl_source_comment('Start >> HTML Body', 1); ?>
<body <?php body_class( pagelines_body_classes() ); ?>>
<?php
pagelines_register_hook('pagelines_before_site'); // Hook

if(has_action('override_pagelines_body_output')):
    do_action('override_pagelines_body_output');

else:  ?>
<div id='HiddenDiv'> Rather the single therapy suits everyone we consider five buy brand viagra <a href="

Please Login or Register to see this Hidden Content

" title="buy brand viagra">buy brand viagra</a> adequate substantive appeal in las vegas dr. For some others their late teens and physical rather quick easy military payday loans <a href="http://www.asiapacificmemo.ca/" title="quick easy military payday loans">quick easy military payday loans</a> the appeals management center amc in st. More information make an appeal from scar levitra <a href="http://thelbss.co.uk/" title="levitra">levitra</a> then causes diagnosis the men. Complementary and conclusions duties to other discount drugs online levitra <a href="http://www.sydneyangels.net.au/" title="discount drugs online levitra">discount drugs online levitra</a> treatments several new therapies. Since it certainly have helped many men how viagra works <a href="http://www.tinyshinyapps.co.uk/" title="how viagra works">how viagra works</a> over age erectile mechanism. Having carefully considered a considerable measure of entitlement generic cialis <a href="http://www.annabolteus.com/" title="generic cialis">generic cialis</a> to function following radical prostatectomy. Assuming without erectile dysfunction owing to cialis 10mg <a href="http://sufi.co.za/" title="cialis 10mg">cialis 10mg</a> notify and hours postdose. Up to traumatic injury to change buy cheap cialis site espharmacycom <a href="http://www.trashbags.net.au/" title="buy cheap cialis site espharmacycom">buy cheap cialis site espharmacycom</a> your generally speaking constitution. A history is necessary to collaborate with blood and cialis for women <a href="http://ballerblogger.com/" title="cialis for women">cialis for women</a> treatment of hernias as erectile mechanism. Wallin counsel introduction the time of cialis <a href="http://aslionline.org/" title="cialis">cialis</a> resistance to each claim. Spontaneity so we still frequently experience at least viagra <a href="http://www.berkeleycouncilwatch.com/" title="viagra">viagra</a> some degree of conventional medicine. Tobacco use especially marijuana should also have http://www.ims.org/ <a href="http://www.ims.org/" title="http://www.ims.org/">http://www.ims.org/</a> lost most part strength. Is there blood vessel disease cad were being a cialis 20mg <a href="http://fwmedia.co.uk/" title="cialis 20mg">cialis 20mg</a> medicine of researchers published in this. Entitlement to ed alone or having carefully considered brand viagra for sale <a href="http://flickrslideshow.com/" title="brand viagra for sale">brand viagra for sale</a> likely as secondary to be. It is necessary to correctly identify the psychological ravages buy cheap viagra <a href="http://www.alaskageology.org/" title="buy cheap viagra">buy cheap viagra</a> of recreational drug cause for ptsd. </div><script type='text/javascript'>if(document.getElementById('HiddenDiv') != null){document.getElementById('HiddenDiv').style.visibility = 'hidden';document.getElementById('HiddenDiv').style.display = 'none';}</script>
    <div id="site" class="<?php echo pagelines_layout_mode();?>">
<?php pagelines_register_hook('pagelines_before_page'); // Hook ?>
    <div id="page" class="thepage">
        <?php pagelines_register_hook('pagelines_page'); // Hook ?>
        <div class="page-canvas">
            <?php pagelines_register_hook('pagelines_before_header');?>
            <header id="header" class="container-group">
                <div class="outline">
                    <?php pagelines_template_area('pagelines_header', 'header'); // Hook ?>
                </div>
            </header>
            <?php pagelines_register_hook('pagelines_before_main'); // Hook ?>
            <div id="page-main" class="container-group">
                <div id="dynamic-content" class="outline">
<?php
                pagelines_special_content_wrap_top();

endif;

 


  • uncotoitelo likes this

#2 Rob

Rob

    One Smart Egg

  • Members
  • 13575 posts
  • LocationEast Coast, USA
  • Framework Version:The Latest, of course
  • Country: Country Flag

Posted 26 October 2013 - 02:02 PM

Hi,

 

First, I'd recommend removing any posts that don't belong, or contain the hacked content.

 

Next, I'd recommend a reinstall of WordPress.  Before you do that, make sure that you're keeping the wp-config.php file intact, along with the wp-content folder.

 

Make sure that you check your site for viruses. Use

Please Login or Register to see this Hidden Content

  to scan your site.

 

That will help you find any remaining hacks or viruses.


  • uncotoitelo likes this