• Hi

    I am using WordPress 4.0 with Active Plugins: akismet/akismet.php,all-in-one-favicon/all-in-one-favicon.php,all-in-one-seo-pack/all_in_one_seo_pack.php,ap-gravatars/ap-gravatars.php,better-wp-security/better-wp-security.php,bm-custom-login/bm-custom-login.php,broken-link-checker/broken-link-checker.php,bwp-google-xml-sitemaps/bwp-simple-gxs.php,exclude-pages/exclude_pages.php,far-future-expiry-header/far-future-expiration.php,flexi-pages-widget/flexi-pages-widget.php,font-uploader/font-uploader-free.php,fv-gravatar-cache/fv-gravatar-cache.php,google-analytics-for-wordpress/googleanalytics.php,google-language-translator/google-language-translator.php,image-widget/image-widget.php,jetpack/jetpack.php,link-library/link-library.php,link-manager/link-manager.php,maxbuttons/maxbuttons.php,nnd-custom-gravatar/nnd-custom-gravatar.php,orderli/orderli.php,php-execution-plugin/php_execution.php,pie-register/pie-register.php,revision-control/revision-control.php,search-and-replace/search-and-replace.php,twenty-eleven-theme-extensions/moztheme2011.php,ultimate-tinymce/main.php,wordpress-form-manager/wordpress-form-manager.php,wordpress-importer/wordpress-importer.php,wp-invoice/wp-invoice.php,wp-special-textboxes/wp-special-textboxes.php,wp-super-cache/wp-cache.php,wptextresizecontrols/init.php

    My email was suddenly receiving hundreds of ‘Undelivered Mail Returned to Sender’ emails. After some investigation I discovered a few minutes before the emails began there was a file created in wp-content/plugins/php-execution-plugin/includes called inc.php which was sending the spam emails.

    How do I find out how inc.php was created?

    How do I prevent other simular files being created?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Hi allanit, same problem here, a spam inc.php code in themes/striking_r, most important question: have you find a solution to get rid of the code?

    Thanks in advance!

    Thread Starter allanit

    (@allanit)

    Yes. The simplest way to get rid of it is to install the Wordfence plugin. It will require a bit of configuration on its settings page but I found the support to be excellent and then run a scan. Wordfence will then recommend things to fix.

    If that does not work get back and I will try to remember the steps I took to manually remove it from the first site I found it on.

    Hi allanit,

    I put in an image folder for all of my sites for images that I put into widgets and I have two php files in that folder one called wp-system.php and one called wp-inc.php. How do they get there? These files start with

    <?php $_F=__FILE__;$_X=

    and then are thousands of jumbled symbols and letters (which I gather execute something). Is Wordfence a good plugin to help with this? And can I delete these files?

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Spam inc.php found in wordpress site’ is closed to new replies.