Clear Malware From Wordpress Website
Budget: $30 – $250 USD
Hi
I have a website that needs to be cleaned and secured, the information below is what I recieved from my ISP about the issue.
The website URL is - https://francointernational.co.za/
What you need to do:
Have your website cleaned and secured
Change all passwords relating to the website, incl database and CMS login credentials (where applicable)
If your website uses a CMS with an administrator interface e.g. WordPress, Joomla or Drupal, check if additional users were created by the hackers, and delete them
Ensure that all website administrators are making use of up-to-date anti-malware software on computers used to administer the website.
Clean and secure your website:
You need to download, clean and secure the website before uploading it again. (Note: remove the index.php holding page now present when re-uploading the website.)
Although you can restore your website content via our Restore Backup tool in konsoleH to a previous version, this version may also be vulnerable or infected. Merely removing the malicious content will not resolve the problem and will not prevent future abuse; the cause of the vulnerability needs to be fixed.
How to reset your FTP password: https://xneelo.co.za/help-centre/website/how-do-i-change-my-ftp-password/
Cloudbric:
Once cleaned and secured, we suggest that you consider using Cloudbric - a comprehensive website security service now offered by xneelo. We offer a free 1 month trial. See https://xneelo.co.za/cloudbric/
Further technical information:
Below, please find technical information to assist you in the investigation and clean-up process.
All web (HTTP) logs for this domain are available in the ‘www_logs’ folder within the domain’s home folder (FTP root). These logs contain information about the visits to your website and may contain evidence about how the domain was compromised.
A malware scan performed on the website content found the following infections:
/usr/www/users/francaubyh/wp-content/themes/curly/includes/plugins/curly-core.zip: Sanesecurity.Foxhole.JS_Zip_22.UNOFFICIAL FOUND
./wp-content/plugins/wpzip/wpzip.php
./wp-content/plugins/atadetero/keweju.txt
./wp-content/plugins/oxyzun/ekyqak.txt
./wp-content/plugins/apogij/ykysobo.txt
./wp-content/plugins/wpnetty/wpnetty.php
./wp-content/plugins/comopyvy/yfuluz.txt
./wp-content/plugins/ryveparu/ahecuz.txt
./wp-content/plugins/wpputty/wpputty.php
./wp-content/plugins/kyzogonu/kyzogonu.php
Please be advised, however, that the above is not an exhaustive list and that a web developer is required to investigate further. The anti-virus software on our hosting environment is specifically designed for the purpose of maintaining server health and security. Because of the diversity of website infrastructure and code, anti-virus software is not an effective method of finding all infected files added or altered by hackers.
If you require any further information or assistance, you are more than welcome to contact me.
I have a website that needs to be cleaned and secured, the information below is what I recieved from my ISP about the issue.
The website URL is - https://francointernational.co.za/
What you need to do:
Have your website cleaned and secured
Change all passwords relating to the website, incl database and CMS login credentials (where applicable)
If your website uses a CMS with an administrator interface e.g. WordPress, Joomla or Drupal, check if additional users were created by the hackers, and delete them
Ensure that all website administrators are making use of up-to-date anti-malware software on computers used to administer the website.
Clean and secure your website:
You need to download, clean and secure the website before uploading it again. (Note: remove the index.php holding page now present when re-uploading the website.)
Although you can restore your website content via our Restore Backup tool in konsoleH to a previous version, this version may also be vulnerable or infected. Merely removing the malicious content will not resolve the problem and will not prevent future abuse; the cause of the vulnerability needs to be fixed.
How to reset your FTP password: https://xneelo.co.za/help-centre/website/how-do-i-change-my-ftp-password/
Cloudbric:
Once cleaned and secured, we suggest that you consider using Cloudbric - a comprehensive website security service now offered by xneelo. We offer a free 1 month trial. See https://xneelo.co.za/cloudbric/
Further technical information:
Below, please find technical information to assist you in the investigation and clean-up process.
All web (HTTP) logs for this domain are available in the ‘www_logs’ folder within the domain’s home folder (FTP root). These logs contain information about the visits to your website and may contain evidence about how the domain was compromised.
A malware scan performed on the website content found the following infections:
/usr/www/users/francaubyh/wp-content/themes/curly/includes/plugins/curly-core.zip: Sanesecurity.Foxhole.JS_Zip_22.UNOFFICIAL FOUND
./wp-content/plugins/wpzip/wpzip.php
./wp-content/plugins/atadetero/keweju.txt
./wp-content/plugins/oxyzun/ekyqak.txt
./wp-content/plugins/apogij/ykysobo.txt
./wp-content/plugins/wpnetty/wpnetty.php
./wp-content/plugins/comopyvy/yfuluz.txt
./wp-content/plugins/ryveparu/ahecuz.txt
./wp-content/plugins/wpputty/wpputty.php
./wp-content/plugins/kyzogonu/kyzogonu.php
Please be advised, however, that the above is not an exhaustive list and that a web developer is required to investigate further. The anti-virus software on our hosting environment is specifically designed for the purpose of maintaining server health and security. Because of the diversity of website infrastructure and code, anti-virus software is not an effective method of finding all infected files added or altered by hackers.
If you require any further information or assistance, you are more than welcome to contact me.