• Resolved krahentash1

    (@krahentash1)


    Hi, I just signed up and when connecting my page etc it asks if the PHP file is legit, and its 100% not. It also says to create a ticket… so here I am. My site is certainly hacked as I typed in site and my domain name and it leads to other shady places… supper annoying. Please help so I can get this fixed. Thank you

Viewing 6 replies - 1 through 6 (of 6 total)
  • Hi @krahentash1

    (Disclaimer: I am not a Wordfence staff member, just a fellow WordPress user/developer, but here is a clear plan to help get your site back under control.)

    What you are describing is a classic redirect injection (often paired with SEO spam or malicious scripts injected into core files/database). Wordfence is flagging an unrecognized or modified PHP file because the attacker likely placed a backdoor or edited an existing file.

    Here is the recommended sequence to isolate and clean this up:

    1. Take an immediate backup

    Before modifying or deleting anything, generate a full backup of your site files and database via your web hosting control panel (cPanel/Plesk/hPanel). Even a infected backup is crucial so you don’t accidentally lose site content or media if a cleanup goes wrong.

    2. Complete Wordfence Setup & Run a Deep Scan

    Even though Wordfence flagged the file:

    1. Go to Wordfence > Scan > Scan Options and Scheduling.
    2. Select High Sensitivity (this will scan image files for injected code and check outside WordPress directories).
    3. Click Start New Scan.
    4. Wordfence will list the suspicious files and give you the option to view differences or delete/restore original core files.

    3. Replace WordPress Core Files

    Malicious scripts often hook into standard WordPress files:

    • In your WordPress Admin, go to Dashboard > Updates and click “Re-install version [x.x]”. This replaces all official WordPress core files with fresh, clean copies while keeping your content and plugins intact.

    4. Check Root Server Files Manually (via FTP or Host File Manager)

    Attackers frequently modify root directives to force the redirects you noticed:

    • .htaccess (Apache / LiteSpeed): Check if there are rewrite rules redirecting search traffic or specific user agents. You can replace it with the default WordPress .htaccess.
    • index.php and wp-config.php: Check the very top of these files (before <?php or right below it) for long obfuscated strings (eval(base64_decode(...)) or strange include/require lines).
    • .user.ini or php.ini: Look for directives like auto_prepend_file pointing to rogue .php or .ico files.

    5. Reset Credentials & Invalidate Sessions

    Once the files are cleaned:

    • Change your WordPress Admin passwords, database password, FTP/SSH credentials, and Hosting account password.
    • In your hosting file manager or via wp-config.php, update the WordPress Security Salts (WordPress Salt Generator) to automatically log out all active sessions, including any the attacker might have open.

    Wordfence team members monitor these forums regularly and will likely respond with their standard cleaning guide as well, but starting these steps now will help stop the redirect and prevent further damage.

    Thank You

    Thread Starter krahentash1

    (@krahentash1)

    Thank you for replying that is so nice of you, when i click delete file wordfence give me an error which says “Could not delete file wp-content/uploads/.cache/.30d77af1.php. The error was: unlink({WordPress Root}/wp-content/uploads/.cache/.30d77af1.php): Permission denied”

    Hi @krahentash1

    The “Permission denied” error happens because the malicious file or directory has strict file permissions, or it is locked by an immutable attribute (chattr +i). Because PHP running through Wordfence doesn’t have elevated server rights, it can’t delete it automatically.

    Here is how you can remove it:

    1. Delete via Hosting File Manager or FTP (SSH)

    • Log into your hosting control panel (cPanel, Plesk, hPanel, etc.) and open File Manager.
    • Navigate to wp-content/uploads/.
    • Enable “Show Hidden Files” (dotfiles) in your File Manager settings so you can see .cache.
    • Change the file permissions (chmod) of .30d77af1.php and the .cache folder to 755 or 777.
    • Delete the file and folder manually.

    2. Check for File Immutability (If on SSH/VPS)

    If you have SSH access and still can’t delete it as root or cPanel user, run:

    lsattr wp-content/uploads/.cache/.30d77af1.php

    If it has the i (immutable) attribute set, unlock it first:

    chattr -i wp-content/uploads/.cache/.30d77af1.php

    Then delete it:

    rm wp-content/uploads/.cache/.30d77af1.php

    3. Contact Hosting Support

    If you don’t have SSH access or file manager permissions, reach out to your web hosting support team and give them the exact error message and path. They can delete the locked file from the root level in seconds.

    Once deleted, continue with replacing the WordPress core files and updating your credentials as mentioned above!

    Plugin Support wfpeter

    (@wfpeter)

    Hi @krahentash1,

    I’m not sure I follow which of our services asked you to manually confirm the legitimacy of a PHP file, but when a site has been compromized we normally recommend that you make a full backup of the site before making any further changes. In fact, @zebaafiashama’s steps start with this and are also helpful. I won’t try to over-complicate or repeat too much.

    It’s also a good idea to remove any users with administrative access that you don’t recognize as a priority. That’s just in case somebody has created a new account to retain access to your site. It’s possible that an attack vector outside of WordPress has been used, though.

    As a rule, any time I think someone’s site has been compromised I also tell them to update their passwords for their hosting control panel, FTP,  WordPress admin users, and database. Make sure to do this.

    I will provide our site cleaning instructions for you, just in case the steps can help: https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

    Additionally, you might find the WordPress Malware Removal section in our free Learning Center helpful. We provide a site cleaning service should you need further assistance, as do other companies. If you find files that seem suspicious and Wordfence isn’t picking them up, email them to samples @ wordfence . com and we’ll take a look.

    Many thanks,
    Peter.

    Thread Starter krahentash1

    (@krahentash1)

    Ive already accepted it, as I couldnt wait any longer for help.. im just waiting on my host to send through my log in details, yes, i have removed him and i honestly think its from his account as it has his username over everything… so i should make him bloody do it! but once i get logins ill go in and delete it, wordfence must be working as it alerted me they tried to log in overnight, ive put 2fa on too. thanks everyone

    Plugin Support wfpeter

    (@wfpeter)

    Thanks @krahentash1. Hopefully our site cleaning link can also be of use if you are able to clean it yourself with assistance from your host.

    Peter.

Viewing 6 replies - 1 through 6 (of 6 total)

You must be logged in to reply to this topic.