Site hacked, need cleanup help please

Somehow someone keeps adding a google search console verification file to be owner and adds a lot of sitemap files & pages to my site.

During a live chat session, we ran a fresh filescan in Defender and found a few suspicious files, such as 404.php file containing code enabling anyone to upload anything, and change file/folder permissions. :slight_frown:

Can you please help clean this up? Thanks!

  • Nithin Ramdas
    • Support Wizard

    Hi Sandra,

    We cleaned up the website, however, there’s still an infected file name index.php in the public_html folder, which keeps on re-generating with malware content once it’s deleted.

    On further troubleshooting, it seems like the source of the action to re-create the index.php once delete doesn’t seem to come from the current WordPress install, and there are chances that the infected index.php is getting generated from other WP infected install.

    There isn’t an easy way to detect such actions out of the box with Defender Pro, it would require extensive scans for the whole server, would recommend you to bring this issue into your hosting provider’s attention, and check whether they are able to help in finding the root cause of the issue.

    Please do let us know how that goes so that we could check further if needed.

    Regards,

    Nithin

  • Ash
    • Code Norris

    Hello Sandra

    Well, if you have other files or sites on the same server (this is pretty common when you are on a shared server) and then this is possible that the index.php file is infected by other sites/files. This is something we can’t check, or in other word, this is a very time lengthy job for us which is beyond our support scope as well.

    Sucuri is a renowned service provider for security purpose. I never used their service personally though, but AFAIK they are pretty good at this. So, you may consider to contact them to clean the server.

    Let us know how it goes.

    Have a nice day!

    Cheers,

    Ash