Hacklink and ad problem on my site, help please!

Hello friends, today I noticed that a link to an xyz site had been placed on my site. However, I don’t know through which vulnerability or how it leaked in. Someone said it originated from the server. I spoke with the hosting company. They stated that they would investigate. The person who added the link placed it inside the comments.php file. But I think they added it to other places as well. I deleted this ad from the comments.php file. Currently, among the contents I’ve examined, nothing appears except for the comment section of one movie. In other words, this link is only added under one movie, but I couldn’t manage to remove that one either.

Also, I re-added the splash ad code that I had accidentally removed from my site. However, no matter where I added this file code—footer, header, slider, single, slider-singer—it only worked on my homepage. So, the splash ad appears on the homepage. But it doesn’t show up on subpages. Consequently, since the number of visitors entering through subpages is higher, I am experiencing a drastic drop in counts. A problem also occurs when I add it to the theme’s own splash ad section.

I would really appreciate it if there is someone who can help me via Skype regarding these two issues. If I can also get help regarding the source of the vulnerability in the first issue, and assistance on topics like how to renew my SQL, config, etc. files along with their passwords, I would be grateful. Friends who can help, whether paid or free, please get me out of this trouble already :frowning:

Footnote: The site is a movie site. The Keremiya WordPress theme is being used. Friends who are willing to help, I would prefer to communicate via Skype if possible.

  • Tema warez ise shell dediğimiz zararlı dosyalar vasıtasıyla sitenize erişilmiş olabilir veya comments.php de bu link warezi paylaşan kişi tarafından eklenmiş olabilir.
  • Sunucunuzda bulunan başka bir site hack edilerek server rootlanmış dolayısıyla size de erişim sağlanmış olabilir.
  • Wp sisteme kurduğunuz bir eklentiden kaynaklı açık oluşmuş olabilir.
  • Bilgisayarınıza trojen veya rat bulaşmış olabilir.

hocam bilgisayarımda rat olduğunu düşünmüyorum. Tema lisanslı orjinal temadır. Ama diğerleriyle ilgili mi değil mi nasıl öğrenebiliriz. Ayrıca bu linki nasıl silebilirim. comments.php içinde ki ilgili kodu sildim. Ama hala en çok hit alan filmlerimden birisinin içerisinde bu link var.

Site adı nedir hocam bakabilirmiyiz?

istedigin kadar sil hocam incobe ile sifrelenmiş tema dosyasinin icine bak imag.php yada functions icerisine bak kesin oradadir eger sildigin halde tekrar cikiyorsa oradadir yetki vermistir.

size pm atamadım hocam. O yüzden veremedim linkleri.

Hocam functions dosyasını inceledim. Fakat bulamadım. imag.php dosyasını da dizinde bulamadım. Skype bıraksanız detaylı bir görüşsek hocam.

pm attım hocam