The Trojan discovered earlier today, which was found hidden inside the theme named "Eco-blog" and hosted at
http://www.zizapixel.com/wp-themes/eco-blog-theme.html , had following signatures:PHP.RSTBackdoor (Symantec)
Trojan.Shell-2 (ClamAV)
When installing the theme mentioned above, this backdoor PHP shell will install itself to:
wp-content/themes/eco-blog/function.phpWe advise everyone to do a virus scan on any Wordpress themes not downloaded from a reputable source before uploading and installing such theme.