Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.

MODULE FOR 1C-BITRIX

Digital Element

Antivirus: Virus and Trojan Detection

Antivirus: Virus and Trojan Search is a professional module for enhancing website security on the 1C-Bitrix platform. The tool is designed to detect malicious code, web shells, trojans, hidden backdoors, suspicious file modifications, and other signs of site compromise.

Technical details

Published
19 June 2026
Updated
4 August 2026
Version
1.0.4
Installed
Fewer than 50 times
Responsive design
Yes
Composite support
Yes
Compatible with Sites24
No
Developer
Digital Element

What this solution does

Antivirus: Virus and Trojan Search is a professional module for enhancing website security on the 1C-Bitrix platform. The tool is designed to detect malicious code, web shells, trojans, hidden backdoors, suspicious file modifications, and other signs of site compromise. The solution extends the platform's built-in protection mechanisms by providing advanced capabilities for file system analysis, 1C-Bitrix object inspection, and site integrity control.

The module performs comprehensive file scanning for malicious code. It supports analysis of PHP, JavaScript, HTML, .htaccess, and other file types. The system searches for web shells, trojans, backdoors, and malicious loaders. It identifies suspicious constructs, obfuscation methods, and hidden code execution. Analysis of high-entropy (encoded) payloads is performed. Suspicious external URLs, iframes, script injections, and remote code loaders are detected. Files are verified against a database of known malicious SHA-256 hashes. Heuristic detection of web shells based on characteristic behavioral patterns is implemented.

The module supports connecting custom signature files and user databases. It performs static analysis of PHP code using PHPAST without executing scripts. Taint analysis is implemented to track chains of user data transmission to potentially dangerous functions. It detects dangerous calls such as eval, assert, system, shell_exec, include, require, and others. The module analyzes dynamic function calls and loaders. Specialized checks for 1C-Bitrix platforms are included: analysis of Bitrix agents, verification of registered event handlers, analysis of website template connection conditions, verification of database SQL triggers, and rules for detecting suspicious changes in 1C-Bitrix projects. The integrity control function allows creating a baseline snapshot of the file system, identifying new, modified, and deleted files, and monitoring changes in critical directories. Integrity of the 1C-Bitrix core and standard modules is checked separately via checksums when update system data is available. Scanning is available step-by-step through the administrative panel without risking execution time limits. Running checks from the command line (CLI) is also supported for automation and scheduling.

The module provides detailed analysis of file objects with the generation of reports containing threat categories, risk level assessment, and recommendations for further actions. Scan results are tagged for easy filtering and can be exported in JSON format. Suspicious files are handled securely through quarantine isolation, restoration from quarantine, and protection against accidental deletion. A Dry Run mode is implemented to analyze the system without making changes to the file structure. The functionality includes management of file and rule whitelists, as well as a Finding Suppressor tool to hide individual false positives.

The solution is designed for administrators of 1C-Bitrix websites, web studios, technical support companies, system administrators, information security specialists, and owners of online stores and corporate portals.

The module is built on a modern modular architecture that ensures scalability and full integration with the 1C-Bitrix administrative panel. It employs multiple independent analysis methods supplemented by specialized checks tailored to the platform's specifics. The system performs integrity control of the file system and the CMS core.

The module supports automation via CLI and scheduled execution. It generates detailed reports with information about each detection. Suspicious files are safely isolated in quarantine. Scan profiles and sensitivity levels can be configured flexibly. The system supports custom signatures and user-defined databases. Files are not modified automatically without administrator confirmation, ensuring full control over all operations.

During scanning, the module analyzes the website file system, 1C-Bitrix platform objects, and project configuration to identify common signs of compromise. It detects PHP viruses and trojans, web shells, backdoors and hidden access points, malicious loaders, hidden scripts, obfuscated and encrypted code, and suspicious constructs typical of malware.

Special attention is paid to dangerous PHP functions and constructs, including the use of eval(), assert(), create_function(), calls to system(), exec(), shell_exec(), passthru(), proc_open(), dynamic function calls, unsafe include and require statements, and attempts to write or modify files via PHP.

The module performs comprehensive security analysis by detecting suspicious data flow chains from user inputs to dangerous functions using Taint Analysis. It identifies obfuscated and hidden code, including Base64, Gzip/Gzinflate, Hex, and ROT13 encoding, as well as high-entropy strings typical of malicious payloads. The system analyzes multi-stage code hiding methods and suspicious external calls, such as URLs in PHP, JavaScript, and HTML, remote script inclusion, suspicious iframes, remote code loaders, and redirects in .htaccess files. It also checks for matches against databases of known malicious domains.

Threat database verification includes file validation against a database of known malware SHA-256 hashes, detection of known web shell families based on specific signatures, and support for custom signature databases. The module provides specialized checking for 1C-Bitrix platform objects, including Bitrix Agents, Event Handlers, template connection conditions, and database SQL triggers, while also identifying suspicious changes in platform system objects.

Integrity control features enable the detection of new, modified, and deleted files, along with monitoring changes in critical site directories.

The module verifies the integrity of the 1C-Bitrix core and standard modules when checksums are available. It analyzes site configuration, including .htaccess files and the detection of dangerous request processing rules. Executable files in the /upload directory are checked, and system directories along with service files are analyzed. Detected threats are categorized by risk level, and each event is tagged. The system identifies potential false positives and generates detailed reports specifying detection reasons and recommended next steps.

General iT can connect “Antivirus: Virus and Trojan Detection”, configure it and verify the integration with the existing website.

UPDATE HISTORY

What’s new

8 releases
1.0.4 (04.08.2026)Latest update

Minor module improvements.

1.0.3 (31.07.2026)

Minor module improvements.

1.0.2 (16.07.2026)

Minor module improvements.

1.0.1 (10.07.2026)

Minor module improvements.

1.0.0 (08.07.2026)

Version 1.0.0 builds upon the module's separate .htaccess file analysis mechanism and adds comprehensive subsystems for detection, integrity control, reporting, and secure operation.

Structural tags for results and individual findings have been added: engine, risk, path, and entity type tags are available in JSON reports and the interface.

A fast common strings prefilter for regex rules has been added, reducing the load on heavy regular expressions; it can be disabled via settings or CLI.

A normalized hash for text files has been added: a stable SHA-256 hash of content without spaces and line breaks, used for reports, baselines, and future comparisons.

FindingSuppressor has been added: it allows targeted suppression of specific false positives based on a stable fingerprint without excluding the entire file.

AST and taint analysis have been strengthened: findings now include the file path, and taint propagation via assignments, arrays, foreach loops, return values, function parameters, method calls, and static call sinks has been improved.

EntropyAnalyzer has been added to detect long, high-entropy encoded payloads, including base64, hex, and packed PHP or JavaScript strings.

UrlExtractor and UrlAnalyzer have been added to extract external URLs, remote loaders, iframe and script injections, external .htaccess redirects, and to check against a local database of suspicious domains.

A Known Malware Hash Database has been added: it performs SHA-256 verification via prefix-index and full hash matching, ensuring no false positives occur based solely on a prefix.

Import and download of Panelica Malware Signatures into the module's internal format have been added, preserving MIT attribution; the database is not downloaded automatically during installation.

A WebShell Fingerprint analyzer has been added, based on a proprietary synthetic model without copying third-party fingerprint databases.

A custom Baseline / Integrity Scanner has been added to detect new, modified, and deleted files, including enhanced scanning of critical Bitrix paths and PHP files in the upload directory.

Bitrix Core Integrity Checker added for separate verification of the core and standard modules against Bitrix reference checksums, if available via Bitrix UpdateSystem.

Bitrix DB scanners added: checks for b_agent agents, b_module_to_module event handlers, b_site_template template conditions, and MySQL/MariaDB SQL triggers.

Protected RuntimeDirectory added: runtime data is stored outside DOCUMENT_ROOT by default; web-root fallback is available only with explicit opt-in.

Reports enhanced: standard CAdminList tables, tags, tag-based filtering, additional columns for hash, URL, domain, confidence, entropy, DB context, and Core Integrity context.

CLI extended: added parameters for prefilter, normalized hash, entropy, URL analyzer, hash DB, Panelica import/download, WebShell fingerprints, baseline, Bitrix DB scanners, Core Integrity, report export, and version.

Operation security improved: debug information hidden from AJAX responses, permissions for destructive actions strengthened, path exclusions enhanced, protection against parallel scans added, and default exclude paths from the site root implemented.

Smoke tests added for new subsystems: tags, prefilter, normalized hash, suppressions, entropy, URL, hash DB, Panelica, fingerprints, baseline, Bitrix DB scanners, Core Integrity, and default exclude paths.

USER EXPERIENCE

Solution reviews

How does this solution work in a real project? Share your experience and help others choose.

Be the first to share your experience

There are no reviews of this solution on git.ru yet. Tell us what worked well and what could be improved.

Verified purchaseAdd a key if you wish. A verified review gets a badge, priority placement and more rating weight.

Open to every clientJust sign in to your account. A key is optional; all reviews are moderated.

YOUR EXPERIENCE MATTERS

Your review

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

What does the price cover?
The displayed price covers the solution itself. Platform licensing, installation and customisation are checked separately. If the page offers bundles, select the required option before submitting a request.
How do I check compatibility?
Compare the supported editions and solution version in the technical details with your project. Before installing on a live website, we recommend making a backup and checking the solution in a test environment.
How much does this solution’s renewal cost?
The current renewal price is 3,450 ₽. Before you order, a manager will confirm the renewal period and whether it applies to your licence.
Can you help with implementation?
We can help install the module, check its settings and verify how it works in your project. Compatibility with other customisations and the scope of work are assessed before we begin.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot