• dear all,

    need help.
    several of my website were hacked, changed passwords… started everything from 0 (lost 2 databases with hundreds of pages and 1000s of photos) but this is still there.

    this are hacked

    http://herps.nature4stock.com/
    http://plants.nature4stock.com/
    http://lepidoptera.nature4stock.com/
    ...

    this are OK

    http://cosmln.nature4stock.com/
    http://dragonfly.nature4stock.com/
    http://insects.nature4stock.com/

    or at least looks so

    The info is there were I have not deleted everything (for nothing) but on first post/page on the title appear an overlay with messages like milf, sex, boobs… that link to different web addresses. Never clicked on them so don’t know those are not really going in a different direction. When I log in the link are off and i can do few changes inside and after I receive a login problem and the message is ON again. I can’t log in again before closing browser and starting it again.

    Checked the website with scanner like the one from sucuri but nothing all is OK 🙁 .

    Don’t know what else to do and I’m desperate (already lost the work of few years)… any help is appreciated.

    Thank you,
    Cosmin

Viewing 11 replies - 1 through 11 (of 11 total)
  • Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Thread Starter cosmln

    (@cosmln)

    Right now found that one php was “injected” with PHP:Agent-IN[Trj] … now I have to see how to get rid of this.

    Any idea?

    Thanks,
    Cosmin

    Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Won’t that just remove the symptom of the hack?

    Thread Starter cosmln

    (@cosmln)

    Dear Andrew,

    You have to think about me that I’m almost a newbie this is why asked for help.

    I have installed “Anti-Malware and Brute-Force Security by ELI” on http://lepidoptera.nature4stock.com/ but not solved anything. The plugin found some problems but I don’t know what to do next 🙁 .

    Please help,
    Cosmin

    Thread Starter cosmln

    (@cosmln)

    Right now my antivirus “avast” is reporting that a comment.php file is virused … deleted that one from a folder where I think that should not be “wp-content/uploads/…/comment.php” but still the website show those messages.

    🙁

    Thread Starter cosmln

    (@cosmln)

    I think I have solved the problems … any inputs are welcome, will like to receive a confirmation that those links are not there anymore.
    Solved with Anti-Malware and Brute-Force Security by ELI, found the update definition button and after all worked.

    Thank you,
    Cosmin

    Simply installing a plugin is very unlikely to fix your problems, even if it appears to clean up the infection.

    Can you confirm you went through the documents/guides thoroughly that Andrew kindly provided you with?

    Have you tried speaking to your web host about how you were initially infected?

    Hi,
    First step, ask host to recover your site to an older backup.

    Once that is done, then do your best to ensure “all” is updated and “all” passwords related to your hosting account changed.

    There is no instant solution. If the site cannot be recovered someone will need to visually dive in and work to fix all that was broken.

    Thread Starter cosmln

    (@cosmln)

    Colin, us much I know I have looked to everything Andrew sent it to me. But as I have told I’m a newbie, i’m just a biologist and photographer (or try to be).

    No time to do all websites so was a delay in solving the problems. To me no strange links appear anywhere on any website (I have checked this on several different system, on PC and on MAC). But will also send everything to a friend to check them another time.

    The Hack Repair Guy everything was recovered from backup and looks clean with an dexception.
    In http://plants.nature4stock.com/ over the icons with my links I have an empty space and for there looking with inspect element from Chrome I have a code that I don’t recognize and I don’t know how to get rid off.

    [ Malware code deleted ]

    I was not able to find in what file is this code inserted. Anyone seen this code? Know how to get rid of this?

    Thank you,
    Cosmin

    That is looking better for me! Do make sure you speak to your host regardless.

    Thread Starter cosmln

    (@cosmln)

    now I see that the code I have wrote from http://plants.nature4stock.com/ was deleted.

    Here it is again and hope that now can stay here.

    <ul>
    	<script type="text/javascript"><!--
            google_ad_client = "pub-9312294701485395";
            google_ad_width = 125;
            google_ad_height = 125;
            google_ad_format = "125x125_as_rimg";
            google_cpa_choice = "CAEQ6fqXhAIaCO_mwRos0nIlKK2293M";
            google_ad_channel = "2887620906";
            //-->
            </script>
            <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
            </script><ins id="aswift_0_expand" style="display:inline-table;border:none;height:125px;margin:0;padding:0;position:relative;visibility:visible;width:125px;background-color:transparent"><ins id="aswift_0_anchor" style="display:block;border:none;height:125px;margin:0;padding:0;position:relative;visibility:visible;width:125px;background-color:transparent"><iframe width="125" height="125" frameborder="0" marginwidth="0" marginheight="0" vspace="0" hspace="0" allowtransparency="true" scrolling="no" allowfullscreen="true" onload="var i=this.id,s=window.google_iframe_oncopy,H=s&&s.handlers,h=H&&H[i],w=this.contentWindow,d;try{d=w.document}catch(e){}if(h&&d&&(!d.body||!d.body.firstChild)){if(h.call){setTimeout(h,0)}else if(h.match){try{h=s.upd(h,i)}catch(e){}w.location.replace(h)}}" id="aswift_0" name="aswift_0" style="left:0;position:absolute;top:0;"></iframe></ins></ins>
    	</ul>

    and this continue … hope that this code that i have found with inspect element from Chrome can be visible and maybe I can get a solution.

    Thank you Colin, they just really don’t care after more than a week of changing messages just succeeded to receive the backup from them 🙁 .

    Thanks,
    Cosmin

Viewing 11 replies - 1 through 11 (of 11 total)

The topic ‘been hacked’ is closed to new replies.