I have been in a spot of bother. I have seen my wordpress site having unnecassry files added in root all the times. I removed them but after 1-2 mintues new files have been added and wp-blog-header.php file also been modified with some malware code at the top of the file linking those newly created files.
I changed permission of wp-blog-header.php to 444 but when a new file added, its permissions changed to 666 and code added again.
I also installed wordfence which give indication of modified files, i cleaned them and changed permissions to 444 but newly files are still creating. Don’t know what to do.
I also downloaded all files, scanned with antivirus and malwarebytes, they found some code, i removed them and re-uploaded to the server on same domain but files are still adding and wp-blog-header.php file modifying again.
I disabled Rest API, XML-RPC but still no luck. Can anyone suggest me what to do here? How can i resolve this please?
Thanks,
Zack
Please remain calm and carefully follow this guide.
When you’re done, you may want to implement some (if not all) of the recommended security measures.
]]>Will follow this guide.
Zack
]]>