SiteLock-PHP-INJECTOR, SiteLock-PHP-HACKEDBY ???

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
What these things are how they infect our website.

How to get rid of them completely?
 

NullMaster

Well-known member
Null Master
Trusted Uploader
Jul 25, 2018
12,021
22,057
120


 
  • Like
Reactions: Piyu03

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
Thankyou @zorerkek for your reply

what i can do now?

Really disappointed with this situation.
 

NullMaster

Well-known member
Null Master
Trusted Uploader
Jul 25, 2018
12,021
22,057
120
use defender wordpress plugins and scan all site. localhost or server. which one is.
pls look at this.
 
  • Like
Reactions: Piyu03

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
I can't access any of my websites.
So i can't upload any plugins to that websites

Now how can i scan and remove these viruses by cpanel
 

TassieNZ

Premium Uploader and Sometimes Hacker!
Jan 17, 2019
9,014
19,807
120
New Zealand
Do you have FTP access? Deactivate all plugins. Rename and put a # at the end of all of them.

Or do it via cPanel. Go to File Manager/public_html/wp-content/plugins Rename all plugins with a # tag at the end of the name. Hopefully that will give you access to scan.

Use what zorerkek recommended or install and run Anti-Malware Security and Brute-Force Firewall

TassieNZ
 
Last edited:

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
Thank you for your support.

Finally i start a virus scan by my CPANEL and get that:
Every single theme is affected by One Theme which is download form jojothemes

by this theme twenty sixteen, seventeen, nineteen every things has been blocked by SITELOCK HACKEDBY

I got over 60 infected files

some file names are function.php and some of them are random seems to be like wp-vwd.config i don't know but

After finish scanning, i reapaired all of these files and my websites working well.

And did this scan again then there are no more affected files.

This is my first experience that i was hacked by a nulled theme

and i think it worth, i will never do this mistake again.

Thank you for all of you for helping me.
 

vanzina

Active member
Nov 13, 2018
116
152
43
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.
 
  • Like
Reactions: Piyu03

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.


I hate local machines they have a lot of issue in uploading themes, plugins, and as well as activating and deleting is bulk will destroy your setup

but that is true it's all my mistake.
Well thank you
 

Kasabian01

Member
Jul 30, 2018
39
10
8
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.
 
  • Like
Reactions: Piyu03

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.

Actually i have a question
that i got 60 + infected files

and i download one PHP files from these infected files on my computer
and uploaded on VIRUS TOTAL but there are no virus detection for that particular PHP file

And now i have some doubt about VIRUS TOTAL.

Please tell me that if for some reason VIRUS TOTAL not detected any virus for that particular file.

could it detect virus if i uploaded the whole theme with that infected file????
 

Kasabian01

Member
Jul 30, 2018
39
10
8
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.
 
  • Like
Reactions: Piyu03

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
366
212
43
India
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.


Hmm That's my fault i uploaded only one infected file. That's the reason it doesn't detect any virus because we know that php is not a virus until the bad script is linking to some where.
 
  • Like
Reactions: Kasabian01

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu