Hacked Site
-
In November I was hacked with the japanese keyword hack. I went into my cpanel and investigated every file there was. I found multiple files infected with gibberish code and the ever present eval(base64 junk!!!! I also found a number of text files labeled king.txt that displayed this:
[redacted]
I simply hit delete on every file I could find that looked malicious, gibberish and out of place. I am not a developer, coder, designer or security auditor. But when you see things like “hacked by ……” it isn’t hard to draw the conclusion that file doesn’t belong! So I hit delete.
What prompted me to do this investigation was I found a number of indexed pages on google for my site with japanese characters. All in all I have deindexed over 200 of them using the google URL removal tool which can be found here
https://www.google.com/webmasters/tools/removalsI used the other google removal tool and it didn’t remove any of these indexed pages. Using this google removal tool deindexed those japanese pages within hours
https://www.google.com/webmasters/tools/removalsThe problem I am having that none of the wordpress guides or FAQ pages on hacked sites references is how to actually locate, identify or confidently know which files are infected. Yeah it says to use succuri or wordfence scanners. Well I have wordfence installed and was installed prior to this hack. It didn’t stop it. My hosting company has run multiple scans using succurri and their in house malware tool. They have found nothing!!! In fact at one point they blamed google for this.
The wordpress hacked guide infers that a wordpress owner knows how to code, develop or navigate their cpanel or database. I know how to login, but that is about the extent of it. You have millions of website owners that possess the same skill level I have and your not providing any step by step instructions on how to identify and locate these infected files.
I say all of this because after deleting all the files I could find that looked malicious my site still creates one japanese web page every day. EVERY DAY I have to do a google sitewide search for my domain. Copy and paste the url into the google URL removal tool.
My hosting company can not find any reference to the URL I am deleting. They can not find it in the database or the file manager. Sucurri scan says my site is fine. There is no malicious malware, but yet today I found three text files named king.txt and when opening up that file I see this:
[redacted]
So how am I supposed to have any confidence in spending money with wordfence or succurri when there scanners cant find this:
[redacted]
can’t find out which file, database, line of code keeps producing a japanese web page that points to a 404 on my site?
What am I actually supposed to do here? What am I actually supposed to be looking for? What file am I actually supposed to be investigating? What area of my cpanel am I actually supposed to be opening, and what am I actually supposed to be looking for?
No I am not goiing to download my site in an xml format and delete all of my plugins and all of my content and whatever other nonsense you state in your wordpress guide.
What files should I be doing a search for? What should I be searching for in the database? what words, verbiage, symbols, references should I actually be typing into the search box within my file manager or database page to find infected files to finally clean this up once and for all 6 months after the fact?
The page I need help with: [log in to see the link]
- The topic ‘Hacked Site’ is closed to new replies.