Wordpress blog might be infected with malware - how to fix?

Nonilol

Elite Member
Joined
Mar 1, 2015
Messages
1,959
Reaction score
825
Sometimes when clicking on one of my articles in Google search results, I get redirected to a "you won an iphone" landing pages.
This only happens very occasionally and it seems to affect multiple articles/pages. I've only seen it once myself, but had a client and multiple coworkers report this to me.

Wordfence doesn't show anything. How would I go about troubleshooting this and finding the cause?

All plugins are up to date: Borlabs Cookie, Disable XML-RPC, Duplicate Page, Limit Login Attempts Reloaded, Matomo Analytics, One Click Accessibility, Redirection (checked all entries), Wordfence, Wordfence Login Security, WPS Hide Login, Yoast SEO
 
Check the file manager and check the files there. I also experienced the same thing, and still trying to get rid of the shell for quite some time now. :D I can help you find the files if you want, but I cannot help you get rid of them right now. :D
 
Hmmm the security plugins didn't help? Strange lol. :D j/k

Are all the plugins and the theme downloaded from official sources? It sounds like your site has some kind of RFI vulnerability which someone used to upload a shell.

You will need to do 2 things to stop them..

1) Compare the files with what you started with, and see if they introduced some file later. This would have been very easy with git, but I guess you don't have it. So, this will be manual work unfortunately (luckily, you only need the wp-content folder, and not the whole installation. Other files can be replaced with default wp files).

2) You will have to find where RFI vulnerability is, which can be like finding needle in a haystack. Perhaps hire someone to do it.
 
Make sure you had a clean wordpress file uploaded, scan for any malware and update your theme and wp version
 
Some Hosting providers do provide you option to check vulnerabilities in your wordpress installation. Atleast hostinger provides which I check weekly to make sure the plugins installed are good.
 
Easiest way is to buy the starter month on Rocket.net for $1 and let them move and clean the site for you, then if you think they are expensive hosting move the site out and end Rocket subscription.

It´s the one dollar clean my fckn site solution for noobs and people that don´t wanna spend time solving it.
 
Time to upgrade Wordfence to Wordfence Care !
For less than a dollar, damn you got some skills. Never use that shitty plugin myself though .. It´s like tasting Gogol on a Friday night, get´s weird and complicated.

Edit: FCKN hell, $500 a year, you fckn kidding me???????
 
For less than a dollar, damn you got some skills. Never use that shitty plugin myself though .. It´s like tasting Gogol on a Friday night, get´s weird and complicated.

Edit: FCKN hell, $500 a year, you fckn kidding me???????
Why not, the guy is probably already paying 119 a year..
You know when you host with godaddy, and your resource runs out and you upgrade to their next plan and everything is sparkling clean
this is it mate, cough out the extra $371
/s clearly
 
If you have enabled backup of your complete hosting account from Cpanel, its easy to tackle if you didnt update much content on your site after it.
1: if you update your posts and pages, export them with any plugin.
2: restore your acc with backdate and check if malware removed, if you seen not work, try again restoration with more backdate till you got clean website.
3: install atleast 2 security plugin like malcare etc and setup.
4: import your exported posts and pages.
its done :)
 
Sometimes when clicking on one of my articles in Google search results, I get redirected to a "you won an iphone" landing pages.
This only happens very occasionally and it seems to affect multiple articles/pages. I've only seen it once myself, but had a client and multiple coworkers report this to me.

Wordfence doesn't show anything. How would I go about troubleshooting this and finding the cause?

All plugins are up to date: Borlabs Cookie, Disable XML-RPC, Duplicate Page, Limit Login Attempts Reloaded, Matomo Analytics, One Click Accessibility, Redirection (checked all entries), Wordfence, Wordfence Login Security, WPS Hide Login, Yoast SEO
Sometimes, due to the issue of malware injection on your wordpress files it would be caused.

Check your wordpress theme plugins and files . If any new file added unwantedly remove with that updated setup.
 
Usually, simply updating the theme/plugins removes the problem. Before that you'd need to restore all the files and db from backup or remove malicious code yourself. If there's a nulled theme/plugin - get rid of them.

Security plugins won't help with cleaning malware.
 
Back
Top