Index.php is infected and can't delete or edit :-(

armom

Regular Member
Joined
Dec 29, 2012
Messages
381
Reaction score
76
Hi guys,
Need help.

My website was hacked recently and all the files were deleted. Then I could somehow get back the websites with the backups but there is still an infected file left. I found it with Wordfence Scan.

The file is Index.php. But now I can't delete/edit/replace this file :-(

Whether I delete/edit/replace this file, it reappears again with the same infected texts in it.

What should I do now? :-(
 
If it re-appears the infection is still there. Try disabling all other plugins and swap to default theme. If it keeps re-appearing then your database is infected too. Best would be to save your texts and start from scratch (delete everything including the database).
 
There’s likely an infected file sitting in another folder that is recreating the index.php. To start, delete your plugins folder. If you have cpanel or root access there’s no reason you can’t login and delete the file. There’s likely a folder or script file sitting somewhere in your public_html folder that is executing and needs to be deleted along with the sub files it creates.

I highly advise you to change your database password and Wordpress admin passwords as well.
 
if its reappearing them most probably hacker have another backdoor access.

I suggest you take the backups of databases and full clean your webspace.

change all the passwords like ftp,dbs,cpanel hosting etc.

Then import the website again.

If the problem still persists then change your host their servers might have gotten rooted by hackers.
 
There is still a backdoor. You may have to check for the backdoor as that is what keeps giving access to the hacker.
 
Like everyone says here if it keeps coming back something is still there you're either going to have to do a deep deep cleanse of everything saving only the essentials or start tediously looking for whats infected.
 
I have already changed the database username and password as well as the wordpress username and passwords.

How can I find the files that's recreating the index.php. The virus scanner just catches the index.php and yes it has some weird codes in it. If i edit this and save it, then open the file again, the texts are there again :-(

I have 5 websites running on a cpanel, all of them have the same problem. Their index.php keeps reappearing :-(
 
If it re-appears the infection is still there. Try disabling all other plugins and swap to default theme. If it keeps re-appearing then your database is infected too. Best would be to save your texts and start from scratch (delete everything including the database).
database is infected too

There is no such thing.


OP, get a backup of the content, and rebuild the website.
 
How long does it take for your index file to be replaced?

Is it immediately, or after a few minutes +?

The reason I ask is because this replacement may be carried out by a cron job, I would look for any jobs running in your cPanel.
 
database is infected too

There is no such thing.


OP, get a backup of the content, and rebuild the website.

Done this too :-(
I got a new cpanel account where I uploaded everything new.
Before my all websites were gone and deleted. Then I got a new cPanel account. Then re uploaded the backup files. Still same :-(
 
It is automated, there's a root kit in your wesite. You may have to check through your Cron job as someone suggested.
Quick question: Do you visit your live website before it starts replicating?
 
Done this too :-(
I got a new cpanel account where I uploaded everything new.
Before my all websites were gone and deleted. Then I got a new cPanel account. Then re uploaded the backup files. Still same :-(
DO not upload anything, copy-paste the texts and rebuild.
 
It is automated, there's a root kit in your wesite. You may have to check through your Cron job as someone suggested.
Quick question: Do you visit your live website before it starts replicating?

What is Cron job?

No, the index.php comes back automatically whether I edit/delete/replace. I don't visit the live site.
 
A cron runs a script at intervals (5secs, per min)
You may want to have someone take a look for you. This may be your your best bet as I suspect that the Server may have been rooted.
 
A cron runs a script at intervals (5secs, per min)
You may want to have someone take a look for you. This may be your your best bet as I suspect that the Server may have been rooted.
My hosting provider is looking for this but it seems like they are not being able to do this. We are working on this issue since yesterday and still no solution. :-(
 
have you got access to the information code that written on the index.php page ...

this code might give a clue where the file that makes the infected index.php pages are?

post the code that you suspect being the problam from your index.php page .

if can not post on here post on a free online scrap book so we can see the code in question .

just post the url .
 
have you got access to the information code thsf written on the index.php page ...

this code might give a clue where the file that makes the infected index.php pages?

Yes, I can see the code but I don't understand what it is. There are some random stuffs going on with gibberish texts.
 
My hosting provider is looking for this but it seems like they are not being able to do this. We are working on this issue since yesterday and still no solution. :-(
Maybe you should get someone from BHW to look into it for you. You should also share the code in the index.php here so we can have a look.
 
Maybe you should get someone from BHW to look into it for you. You should also share the code in the index.php here so we can have a look.

I don't know if it's allowed to share the code here.
 
Back
Top