Support

Home Forums Event Espresso Premium RTdoc malware

RTdoc malware

Posted: October 7, 2015 at 1:37 pm

Viewing 1 reply thread


Brunswick Topsham Land Trust

October 7, 2015 at 1:37 pm

WP Engine found malware on our site http://btlt.org that appears to be located and initiated from the database in conjunction with perhaps other areas. The malware causes redirects to popup ads and suspicious intent websites.

Here is a log of where this software has been first spotted in the execution stages: https://pastebin.sucuri.net/evxbit4zh1

Having run several malware tests from within WordPress, the results come back negative, nothing found.

Does anyone know of any method of removing this? I do not know that much about accessing EE database tables. Do not want to crash anything.


Josh

  • Support Staff

October 7, 2015 at 2:10 pm

Hi there,

For those message templates, those can be edited in the Messages editor. So what you can do is look in phpmyadmin for the rows that have the 6 IDs listed, then go to edit those messages. You can even reset some of the templates right from the messages editor if they’re really messed up.

I can advise contacting Sucuri or another professional to help clean up the post and postmeta tables.

Viewing 1 reply thread

The support post ‘RTdoc malware’ is closed to new replies.

Have a question about this support post? Create a new support post in our support forums and include a link to this existing support post so we can help you.

Event Espresso