Quote:
Originally Posted by nxtgen
Nevermind.
|
The mail notification showed me some code which is typical for malware. They change urls or text in the style cache, while the original style seems ok. In the specific case, they injected a script tag, which then moves the visitor away from your site. You can remove erratic style information in the cache by saving or reverting one template.
However, if you host an offending plugin, they can get in again and again. A good place to look at is the misc.php script, which offers a few entry points for highly advanced coders.