• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

SiteLock-PHP-INJECTOR, SiteLock-PHP-HACKEDBY ???

Piyu03

Active member
Trusted Seller
Trusted Uploader
Feb 24, 2019
367
213
43
India
What these things are how they infect our website.

How to get rid of them completely?
 


 
  • Like
Reactions: Piyu03
Thankyou @zorerkek for your reply

what i can do now?

Really disappointed with this situation.
 
I can't access any of my websites.
So i can't upload any plugins to that websites

Now how can i scan and remove these viruses by cpanel
 
Do you have FTP access? Deactivate all plugins. Rename and put a # at the end of all of them.

Or do it via cPanel. Go to File Manager/public_html/wp-content/plugins Rename all plugins with a # tag at the end of the name. Hopefully that will give you access to scan.

Use what zorerkek recommended or install and run Anti-Malware Security and Brute-Force Firewall

TassieNZ
 
Last edited:
  • Like
Reactions: Babak and Piyu03
Thank you for your support.

Finally i start a virus scan by my CPANEL and get that:
Every single theme is affected by One Theme which is download form jojothemes

by this theme twenty sixteen, seventeen, nineteen every things has been blocked by SITELOCK HACKEDBY

I got over 60 infected files

some file names are function.php and some of them are random seems to be like wp-vwd.config i don't know but

After finish scanning, i reapaired all of these files and my websites working well.

And did this scan again then there are no more affected files.

This is my first experience that i was hacked by a nulled theme

and i think it worth, i will never do this mistake again.

Thank you for all of you for helping me.
 
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.
 
  • Like
Reactions: Piyu03
I recommend always try nulled theme in local and then if you like the purchase.
It's not $60 to change your life.
Theme is always updated and includes support.
To test locally you can use Xampp, Mamp, WampServer, DesktopServer.


I hate local machines they have a lot of issue in uploading themes, plugins, and as well as activating and deleting is bulk will destroy your setup

but that is true it's all my mistake.
Well thank you
 
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.
 
  • Like
Reactions: Piyu03
Hey PP3333, sorry to hear this. I had a similar situation on one of my old servers when a compromised Wordpress installation infected all the websites hosted. I was forced to destroy everything to get rid of the problem. I do advocate to avoid nulled themes and plugins on production websites, but I'd like to point out I have never had any issue with components downloaded from here. Said that, I recommend to scan on VirusTotal any theme/plugin zip (from any source) before uploading to live websites. Also, Wordfence can help sometimes.

Actually i have a question
that i got 60 + infected files

and i download one PHP files from these infected files on my computer
and uploaded on VIRUS TOTAL but there are no virus detection for that particular PHP file

And now i have some doubt about VIRUS TOTAL.

Please tell me that if for some reason VIRUS TOTAL not detected any virus for that particular file.

could it detect virus if i uploaded the whole theme with that infected file????
 
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.
 
  • Like
Reactions: Piyu03
Quoting VirusTotal website: "VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content"

As far I know, it will detect any infected file containing code/script which has been already scanned and marked as malware. You can try uploading the entire folder to see if the result is different.


Hmm That's my fault i uploaded only one infected file. That's the reason it doesn't detect any virus because we know that php is not a virus until the bad script is linking to some where.
 
  • Like
Reactions: Kasabian01
this fourm is awesome. i am here science last month and from that month i only found and use resources from this fourm.

Not even try to find any other website.
Hello PP3333,

Has your issue been resolved? if not, let me know, I will personally investigate it if you like.
 
  • Love
Reactions: Piyu03
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock