here's the running processes
Meanwhile, on another heavily infected website
208 Malware created plugins
Deleted WEB4 totally from ISPCONFIG, deleted all DBs related to the website
Recreated new website, now WEB17
went into directory, and...
yes, i downloaded totally fresh in the empty web directory from wordpress
root 1519924 0.0 0.0 12140 1164 pts/1 S+ 05:32 0:00 grep --color=auto web17
to provide an update:
i deleted all of the files under /web
i created a new DB with new user
I installed a fresh version of wordpress,...
the above have the malware
i have another 4 or 5 sites which either do not use wordpress, or are not as active so no...
Yes, the malware is on other wordpress sites as well
No they are not all owned by web4 but owned by their own webX
Herewith active crontabs, i...
noted, will try as suggested.
I have a strong suspicion that the malware is in the database... any scanner which can scan DB's or what can i look...
well noted, will try that.
[root@server1 wp-content]# crontab -l -u web4
no crontab for web4
I AM NOW DESPERATE
Honestly, i have tried everything i can think of.
i deleted the all files under /web
i installed fresh wordpress files
Separate names with a comma.