My site hacked with a Paypal phishing scam set up on it.
-
Could someone please give me some advice.
My site has been hacked. I have been arguing with my host for two full days via email and they are driving me crazy. They are sending me stock response after stock response (they clearly only speak very basic english, and are not comprehending anything I’m asking). They keep telling me they have scanned it and deleted one file and now it’s fine.. 50 or so emails from them later over two days and I can’t get a single coherent answer to my questions other than stock responses to change my password. They keep telling me it’s fixed (it’s not), then saying have a good day and they’re glad they could help me (WTF?!!!). Then each time it’s followed up with them starting a new support thread saying “hey, your site has been comprimised”, etc, suspending my account and the whole process starts again …. ugh. Yes, it’s as frustrating as it sounds.
OK, to the question… in the public_html folder there is a folder that I have never seen before called ‘webapps’. It’s full of folders with files for banking and paypal scams. (Login.phps, spoof bank sites, images, logos, etc, etc.. my host keeps insisting the’ve got rid of everything that was put in my account by the hacker, because their scan says so.). Should that webapps folder be there for any legitimate reason, or can I make this simple and just ask them to delete the entire folder? (They’ve changed permissions on some of the folders in there, so I can’t remove them myself.)
I have never seen the ‘webapps’ folder before, it’s not in any of my site backups. I don’t have any ecommerce or anything set up on my site. It’s just a simple wordpress installation with basic plugins (Akismet, Broken Link Checker, Content Protector, Jetpack, WP-Footnotes, Twidget, and WP-Cleanup).
Can anyone who knows what they’re talking about (more than me, and exponentially more than the nitwits on the support desk who are making me crazy), tell me if deleting the entire webapps folder sounds like the right course of action? Or is it required for something that I am not aware of?
Apologies for the rant, trying to be thorough, before I go completely postal. Please send help. ??
Cheers,
Sam
- The topic ‘My site hacked with a Paypal phishing scam set up on it.’ is closed to new replies.