What's new
  • Our resources on Babiato Forum is CLEAN and SAFE. So you can use it for development or production. But sometime the antivirus will warn the JS code. It's no problem. So before downloading, you need to disable the antivirus tools and then enjoy your "Party"!

SiteLock-PHP-INJECTOR, SiteLock-PHP-HACKEDBY ???

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
What these things are how they infect our website.

How to get rid of them completely?
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
Thankyou @zorerkek for your reply

what i can do now?

Really disappointed with this situation.
 

zorerkek

Well-known member
Null Master
Joined
Jul 25, 2018
Messages
635
Reaction score
565
Points
93
use defender wordpress plugins and scan all site. localhost or server. which one is.
pls look at this.
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
I can't access any of my websites.
So i can't upload any plugins to that websites

Now how can i scan and remove these viruses by cpanel
 

TassieNZ

Member
Joined
Jan 17, 2019
Messages
50
Reaction score
27
Points
18
Do you have FTP access? Deactivate all plugins. Rename and put a # at the end of all of them.

Or do it via cPanel. Go to File Manager/public_html/wp-content/plugins Rename all plugins with a # tag at the end of the name. Hopefully that will give you access to scan.

Use what zorerkek recommended or install and run Anti-Malware Security and Brute-Force Firewall

TassieNZ
 
Last edited:

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
Thank you for your support.

Finally i start a virus scan by my CPANEL and get that:
Every single theme is affected by One Theme which is download form jojothemes

by this theme twenty sixteen, seventeen, nineteen every things has been blocked by SITELOCK HACKEDBY

I got over 60 infected files

some file names are function.php and some of them are random seems to be like wp-vwd.config i don't know but

After finish scanning, i reapaired all of these files and my websites working well.

And did this scan again then there are no more affected files.

This is my first experience that i was hacked by a nulled theme

and i think it worth, i will never do this mistake again.

Thank you for all of you for helping me.
 

vanzina

New member
Joined
Nov 13, 2018
Messages
22
Reaction score
19
Points
3
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.

I hate local machines they have a lot of issue in uploading themes, plugins, and as well as activating and deleting is bulk will destroy your setup

but that is true it's all my mistake.
Well thank you
 

Kasabian01

New member
Joined
Jul 30, 2018
Messages
7
Reaction score
3
Points
3
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.
Actually i have a question
that i got 60 + infected files

and i download one PHP files from these infected files on my computer
and uploaded on VIRUS TOTAL but there are no virus detection for that particular PHP file

And now i have some doubt about VIRUS TOTAL.

Please tell me that if for some reason VIRUS TOTAL not detected any virus for that particular file.

could it detect virus if i uploaded the whole theme with that infected file????
 

Kasabian01

New member
Joined
Jul 30, 2018
Messages
7
Reaction score
3
Points
3
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.

Hmm That's my fault i uploaded only one infected file. That's the reason it doesn't detect any virus because we know that php is not a virus until the bad script is linking to some where.
 

PP3333

Active member
Joined
Feb 24, 2019
Messages
115
Reaction score
26
Points
28
https://www.jojo-themes.net/ used to have some good and hard to find items. However, 90% are now virused and I would never go near it.

TassieNZ :)

this fourm is awesome. i am here science last month and from that month i only found and use resources from this fourm.

Not even try to find any other website.
 

Similar threads


Forum statistics

Threads
5,910
Messages
21,100
Members
18,854
Latest member
britlife