How to remove a virus from a WordPress website — step by step
How can you tell if your WordPress website is infected?
An infected WordPress website often shows no obvious signs at first glance, especially when the attack is well concealed. However, there are several characteristic symptoms that should concern you:
- The website redirects users to suspicious sites with ads or phishing pages
- Strange pages appear in Google results — in Japanese or Russian, or with adult content
- Google Search Console displays a warning about “malware” or “phishing”
- Your hosting provider has suspended the account because of spam distribution or excessive CPU usage
- Unknown administrator accounts appear in the WordPress dashboard
- Server file modification dates have changed without your knowledge
Even one of the above is a warning sign. The sooner you respond, the smaller the losses — both to your reputation and your Google rankings.
Step 1 — Make a backup BEFORE deleting anything
It may sound counterintuitive, but make a complete backup of the server before you start cleaning: all files and the database. First, once a file has been deleted, you will not be able to analyze it. Second, your hosting provider may block the account at any time, in which case access to the data will be lost.
Use phpMyAdmin to export the database (SQL format), and FTP/SFTP or the File Manager in your hosting panel to download the files. If you have SSH access, the fastest method is the command:
tar -czf backup_$(date +%F).tar.gz public_html/
Step 2 — Check file modification dates
Malicious code is physically placed in a file on the server. The fastest way to locate infected files is to check which files were modified most recently without your knowledge.
Run this command over SSH:
find public_html -name "*.php" -newer public_html/wp-config.php -ls
You will get a list of all PHP files modified after the WordPress installation date. Every suspicious file needs to be reviewed manually.
Step 3 — Scan files for known malware signatures
Malicious PHP code has characteristic patterns. Look for occurrences of the following functions and patterns:
eval(base64_decode(...)) — obfuscated executable code
system(), exec(), passthru() — execution of system commands
preg_replace('/./e', ...) — rarely used and often malicious
$_POST['cmd'], $_GET['x'] — web shells that accept commands through a URL
- Long base64-encoded strings (they look like random A-Za-z0-9+/= characters)
Over SSH, search like this:
grep -r "eval(base64_decode" public_html/ --include="*.php" -l
Step 4 — Remove malicious code or infected files
Once you have a list of infected files, you have two options:
- Replace them with files from the original installation — for example, if
wp-login.php is infected, download a clean version from wordpress.org and replace the file.
- Remove the malicious section — if the infection affects your theme or a plugin, remove only the injected block of code. Note: after removing it, make sure the file is still syntactically valid.
Never delete the wp-config.php file — it contains database access credentials.
Step 5 — Check the database
Malware increasingly injects malicious code into databases — especially into the wp_options table (the active_plugins, siteurl, and home options) and post content in wp_posts.
Run these queries in phpMyAdmin:
SELECT * FROM wp_options WHERE option_value LIKE '%eval(%';
SELECT * FROM wp_posts WHERE post_content LIKE '%<script%' AND post_status = 'publish';
Every result needs to be analyzed — not every <script> is malicious, but each one should be known and intentional.
Step 6 — Change ALL passwords and keys
After cleaning the website, be sure to change:
- The WordPress administrator password (and those of all users with the Admin/Editor role)
- The database password in
wp-config.php and in the hosting panel
- The FTP/SFTP password
- The authentication keys in
wp-config.php (the AUTH_KEY, SECURE_AUTH_KEY, etc. section) — generate new ones at api.wordpress.org/secret-key
- The password for the hosting panel / cPanel / Plesk
Step 7 — Update WordPress, themes, and plugins
The vast majority of WordPress hacks result from outdated plugins or themes. After cleaning, promptly update everything to the latest versions. If a plugin has not been updated for more than a year, consider replacing it with an actively maintained alternative.
When is self-service cleanup not enough?
The method described works for simple infections. However, many advanced attacks leave multi-layered backdoors — even after the homepage is cleaned, the virus returns because a hidden script in the cache directory, a child-theme folder, or the database was overlooked.
If the infection returns a few days after cleanup, that is a sign the attack is deeper than it appears on the surface. In that situation, you need a professional analysis of server logs, an audit of all files, and a review of the server configuration.
That is exactly what we do at WebRatunek — WordPress malware removal. We provide a full report describing what we found, what we removed, and how we secured the website against another attack. With a 30-day warranty.