I am going to share my story here. I have some websites but have rare time to work for my own websites as I am freelancer so I need to work for others most of time. Since one week my different friends were telling me about my websites that your this site has these header error blah blah, I was watching but I thought it is due to some of my or any of my friends’ fault who try to install some new script which doesn’t match with website and now we are facing error. but then yesterday my friend shown me, my main website
it has some errors on the top, I google for it but haven’t get any good answer, I joined lots of forums and posted my problem on each forum to get some good solution but I was unable to get some good solution.
Error was something like:
Warning: session_start() [function.session-start]: Cannot send session cache limiter – headers already sent (output started at /home/eitlabs1/public_html/salmanoreen.com/index.php:1) in /home/eitlabs1/public_html/salmanoreen.com/libraries/joomla/session/session.php on line 423
Warning: Cannot modify header information – headers already sent by (output started at /home/eitlabs1/public_html/salmanoreen.com/index.php:1) in /home/eitlabs1/public_html/salmanoreen.com/libraries/joomla/session/session.php on line 426
I checked these directories many times and try to resolve problem but I was unable to do anything. yes it was wasting my time
I had lots of other tasks to do.
then I found this website http://sitecheck.sucuri.net and checked my website here. I was not happy to see my website status Site infected with malware
Now the basic question was what to do?
My brother suggested me to change hosting and my friend suggested me to talk with justhost (my hosting provider).
For brother solution: I thought, alright I can move my website but what about other websites? should I move all websites? ohh NO it is tooo time consuming task and how about if my brother hosting will infect one day? Will I move again?
these were questions in my mind.
I contact to my hosting and I found Mr. Bill there. He was nice man, he told me it is script injection and he removed from my main website. now there were no more errors on my website. but then chat get closed, I tried many times to found mr. bill again but I couldn’t found him again, other support team was saying that I should hire some professional to secure my website.
ohh it was really expensive to hire some professional for our testing and personal websites.
but at least I found the solution that we can remove this malware script from website. now the main tension was where this script can be placed.
I again checked http://sitecheck.sucuri.net and scan my other website there. I found following javascript malware:
and I start searching this code in all of my website files, I found same code in index.php
I removed this all code from each website and all websites start working perfectly, now my all websites are error free again.
This all was time consuming but finally. I have solved my problem.
Moral: there shouldn’t be any thing before <?php if you have some code then that can be malware, simply remove it.






