Wordpress Malware - How "disinfect" ?

Hi All - My question is: What do I do to get rid of MalWare in a WordPress website (or any website for that matter)? (Linux/LAMP server if that matters)

Some specifics:

I have a Wordpress site that was hacked into, and now I have Spam being generated that looks like we are sending it. I bought Backup Buddy, ran it's MalWare inspector, and it warned me that:
Malware Security warning in the URL:
    *Known Spam detected. Details: http://sucuri.net/malware/entry/MW:SPAM:SEO?s <div><div id="vtip">The    advised dosage by doctors healthy patients, and 5mg of the elderly and malnourished patients, together with <a href="http://higherorderfun.com/blog/list/">ativan without prescription</a> patients with liver failure. The drug is recommended to be taken <a href="http://higherorderfun.com/blog/homepage/">ultram without prescription</a> right before going to bed.</div>

When I do a "View Source Code" of the generated web page, I do also see those uninvited "higherorderoffun" links.  Whatdo I do to get rid of this Malware?
LVL 1
bleggeeAsked:
Who is Participating?
 
Jason C. LevineNo oneCommented:
You need to be able to find the source of the infection.  This is hard to do.  I strongly recommend reading my article:

http://www.experts-exchange.com/Web_Development/Blogs/WordPress/A_10806-Recovering-From-and-Preventing-WordPress-Site-Hacks.html

and then installing WordFence and running a scan with it.
0
 
lenamtlCommented:
Do you have a clean backup that you could use, if so removed everything then upload the clean backup file and DB.
Make sure you update to the latest WP version and plugins.

There also good plugin to add more security,

Sometimes the problem is coming from the server security problem, sometimes it is because of a plugin or a template, also check file permission.

You could also block the IP of the attacker using .htaccess, check your server logs and traffics logs.

I'm using this script, it' not prevent the problem but at least I got an email if this occur and I know the affected files. https://github.com/lucanos/Tripwire
0
 
bleggeeAuthor Commented:
Thanks Jason, WordFence worked great. And the Free version too !
0
 
Jason C. LevineNo oneCommented:
Yes, WordFence may be the best of the bunch for a free product.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.