04-28-2013, 12:02 PM
04-28-2013, 12:02 PM
04-28-2013, 01:13 PM
Sales Page
Mirror
[hide]http://mir.cr/HCUIX0FE[/hide]
Code:
http://www.warriorforum.com/warrior-special-offers-forum/756106-wordpress-lead-gen-theme-seduces-visitors-into-contacting-you-just-re-opened.html
Mirror
[hide]http://mir.cr/HCUIX0FE[/hide]
04-28-2013, 06:52 PM
Nice find!
I would even buy this for clients, if they want a responsive site.
Cheers, Johnny63
I would even buy this for clients, if they want a responsive site.
Cheers, Johnny63
04-28-2013, 06:54 PM
THE ABOVE SHARE FROM yojodavo IS INFECTED
(maybe mirror too, I have not had time to check)
It contains a devious and dangerous infection.
functions.php is infected by encoding the infection with some real parts of the plugin.
by doing that, if you simply remove the encoded bit, the plugin will break
the infection itself creates a new user named wordpress
if then emails 'Wordpress Plugin Lead' to a scumbag at
feel free to abuse and destroy that idiots mailbox as you wish, it's really deserved.. enjoy!!
At that point, he can then go to your domain, login with that newly made account.
he will damage your account and offer to help for a price
or add unwanted conent, backlinks, ads, cpa stuff etc. or even totally hijack your wp installation and lock you out.
!! IMPORTANT !!
If you have used the above shares, look for and remove a user called wordpress if it's there.
Change the password at least!!
Then check for unwanted posts, plugins, modifications etc
I've cleaned it, available here:
So far, this is the 2nd infected share I've reported from this OP today and also reported him for a share where you have to visit and assfly url and complete a survey to get the password to the archive... not good
Cheers,
Si
(maybe mirror too, I have not had time to check)
It contains a devious and dangerous infection.
functions.php is infected by encoding the infection with some real parts of the plugin.
by doing that, if you simply remove the encoded bit, the plugin will break
the infection itself creates a new user named wordpress
if then emails 'Wordpress Plugin Lead' to a scumbag at
Code:
thomasza@gmx.com
At that point, he can then go to your domain, login with that newly made account.
he will damage your account and offer to help for a price
or add unwanted conent, backlinks, ads, cpa stuff etc. or even totally hijack your wp installation and lock you out.
!! IMPORTANT !!
If you have used the above shares, look for and remove a user called wordpress if it's there.
Change the password at least!!
Then check for unwanted posts, plugins, modifications etc
I've cleaned it, available here:
Magic Button :
Code:
http://www.sendspace.com/file/tb3ksl
So far, this is the 2nd infected share I've reported from this OP today and also reported him for a share where you have to visit and assfly url and complete a survey to get the password to the archive... not good
Cheers,
Si
04-28-2013, 07:26 PM
Thanks simey69. Good to know you're looking out for us. +5.
04-28-2013, 07:42 PM
simey69 - you're our Guardian Angel :-)))
BIG THANX to you - always!
Cheers, Johnny63
BIG THANX to you - always!
Cheers, Johnny63
04-28-2013, 08:10 PM
@yojodavo - you should be effin banned, i only wish nothing but the worst for you
@simey69- thanks for checking the files for us , i cant give rep , dont know why maybe because i lose my reps too, anyway thanks again
@simey69- thanks for checking the files for us , i cant give rep , dont know why maybe because i lose my reps too, anyway thanks again
04-28-2013, 11:29 PM
Mirror for Clean
[hide]http://mir.cr/WBSSVNVO[/hide]
[hide]http://mir.cr/WBSSVNVO[/hide]
04-30-2013, 08:52 AM
Thanks simey69!
and Meril!
You are awesome and MAX reps added for you both. I greatly appreciate the work you do.


04-30-2013, 09:26 AM
dudes posting shit files that are infected? he needs to be banned.
that shit ain't cool dude!!!
that shit ain't cool dude!!!