(Help) I think my wordpress site have malware? How to fix it

hims.000

Senior Member
Joined
Apr 10, 2020
Messages
1,022
Reaction score
586
Hi, I am new to WordPress.

sometimes when I open my site [Mod Edit] it redirects to another website. I am using the GeneratePress Premium theme provided by @RoiBox on his giveaway post | As he told "This is my personal buy from GeneratePress, unmodified direct from GeneratePress." ( and a trust RoiBox I think he is a genuine guy ).

I not using other premium plugins.


I don't know why this happens?
How to check malware?
How can I remove them?

help me.
 
Last edited by a moderator:
Firstly, you need to see where the redirect was set, it could be either of (or all of the below);

- wp-config.php file
- htaccess
- index.php
- Database

A more complicated hack could be placed in your theme of plugin headers.

So you should check all of the above locations and remove any malicious lines.

Afterwards,

- Perform a "Manual WP update",
- Delete your plugins and reinstall them
- Download and reinstall the latest version of your theme.
- Remove unused themes and plugins.
- Install a security plugin like Wordfence.

You can go further by;
- Modifying your wp-login URL.
 
From what browser do you access the site? If it's Chrome, for example, make sure you don't have any shady extension installed there (same with Mozilla, etc). Also, make sure you don't have installed any unknown software into your computer.

If the problem is indeed from the website, and not from the browser or due to any shady software, do you have any nulled plugin installed on your website?

+1 for @RoiBox . I personally don't think it is from the theme, and RoiBox is one of the best here.
 
oh... it might be the issue of my hosting.
 
Firstly, you need to see where the redirect was set, it could be either of (or all of the below);

- wp-config.php file
- htaccess
- index.php
- Database

A more complicated hack could be placed in your theme of plugin headers.

So you should check all of the above locations and remove any malicious lines.

Afterwards,

- Perform a "Manual WP update",
- Delete your plugins and reinstall them
- Download and reinstall the latest version of your theme.
- Remove unused themes and plugins.
- Install a security plugin like Wordfence.

You can go further by;
- Modifying your wp-login URL.
thank you I will check
 
From what browser do you access the site? If it's Chrome, for example, make sure you don't have any shady extension installed there (same with Mozilla, etc). Also, make sure you don't have installed any unknown software into your computer.

If the problem is indeed from the website, and not from the browser or due to any shady software, do you have any nulled plugin installed on your website?

+1 for @RoiBox . I personally don't think it is from the theme, and RoiBox is one of the best here.
the same thing happens on mobile also. No nulled plugin was installed on my website.
 
If none of those tips will work, you should move your site into another hosting company (not vps, or dedicated server, but shared hosting would be enough.
 
It has subsidiers that provide free hosting, which is usually used by sраm and mаliciоus shıt. You should stay away from these types of companies.
Can you recommend to me some best hosting at an affordable price?

I think many website are doing affiliate so they suggest those hosting where they can earn from it
 
Can you recommend to me some best hosting at an affordable price?

Namecheap is good enough.

If you don't know tech, contact their support, and give out all your details, they will move for you.
 
Can you recommend to me some best hosting at an affordable price?

I think many website are doing affiliate so they suggest those hosting where they can earn from it
Try hyper.host, price starts at just 4.99 for a reliable hosting, security and support.
 
I use the same theme from @RoiBox so the problem is not coming from there
 
the same thing happens on mobile also. No nulled plugin was installed on my website.
Using no nulled plugins is no guarantee, regular plugins get hacked all the time to when vulnerabilities are found by hackers. Go over the plugins you use and see if you can find any reports online for vulnerabilities of your versions.
 
Using no nulled plugins is no guarantee, regular plugins get hacked all the time to when vulnerabilities are found by hackers. Go over the plugins you use and see if you can find any reports online for vulnerabilities of your versions.
thank you I have fixed the redirection issue
 
What was it? Maybe others can get some value of your experience.
The issue resolve with Wordfence plugin.

I have installed the plugin and start scaning.

.this plugin automatically delete the malware if it found on the website.


Redirection issue have solved here.
 
Back
Top