Thank you. I will give this a try.
I can’t see any that stand as obvious to me, but then I wouldn’t call myself an expert in this.
When I delete the malware code I leave the Index page as this <?/**
If I do anything else the websites wont work. Is there any code I can add in that would prevent the malware from being re-inserted?
Thanks for your help.
I am having exactly the same problem. It gets into any index.php file and uses a .tv web address with various names in front after wiping it manually from each file when it comes back.
It does not only get into WordPress but any website that I have hosted.
There is a very small pixel in top left corner of web browser when site is infected.
I have tried uploading using another PC as it seems to be the PC that gets infected (in this case a MAC!) I have changed passwords and FTP password several times but still have the problem!