How To Fix Hacked WordPress Site & Malware Removal - Real live case

Published: 17 February 2022
on channel: Matt - WPress Doctor
51,674
1.1k

Got hacked? Do not worry! I am here to help you out. In this tutorial we will fix a hacked website step by step. Its a real case so we are about to bumb into some problems.
👇🏻👇🏻👇🏻 Start here 👇🏻👇🏻👇🏻

I hope you can clean your website yourself with this Tutorial! If you cannot get it cleaned or you lack the time, you could hire me to clean your WordPress website: 👉🏼 https://wpressdoctor.com/clean-hacked... 💪🏼

Do you want to support my channel? Leave a like or buy Divi / Elementor Pro with 10% discount via the link below. That will help me enormously to create these free videos for you and keep going!

⇒ Software that I recommend:
✅ Divi 10% discount ⇒ https://wp.discount/divi-discount/
✅ Elementor Pro ⇒ https://wp.discount/elementor-pro-dis...
✅ SiteGround 70% discount ⇒ https://wp.discount/siteground-discount/
✅ WP Rocket 10% discount ⇒ https://wp.discount/wp-rocket-discount/

I want you to succeed with your cybersecurity, so lets get started.

⏱️Timestamps⏱️
0:00 Intro
0:26 Try backups
0:59 Strange Things
1:24 Check your files
3:16 Put the files back
4:47 Download WordFence 👉https://wordpress.org/plugins/wordfence/
5:05 Upload WordFence
5:24 Check strange plugins
6:22 FoxAuto hacktool
8:36 Remove strange plugins
9:40 Run WordFence
10:20 Scan for Malware & virusses
11:15 Clean files
11:50 Check users
13:37 Remove compromised users
14:26 Fresh WordPress install
16:13 A Trojan Horse in WordPress
17:03 Fresh WordPress install
18:43 Still not fixed
19:00 Contact hosting
20:00 Japanese SEO spam
21:20 Check logs files
21:50 Reset FTP passwords
22:45 Replace last files

Thank you for watching! 😀

✅For tips and tricks on getting the most out of WordPress, don't forget to subscribe: https://wpressdoctor.com/sub

📖Transscript📖
Don't panic. The WPress Doctor is here. We're going to fix your hacked website within a couple of minutes. Breathe in, breathe out, because it's going to be all fine.

In this video we're going to fix a hacked website. Someone came to me and he said: "I have a website which is really slow. Can you investigate it?" While investigating i stumbled upon really strange things. But the first thing you need to check for me is; if you have backups. If you log into your hosting company and you can restore backups from yesterday, or two days ago, a week ago a month ago, and the hack is gone, that's perfect! After that you can just install iThemes Security - I made a tutorial about it right here. So you can watch it, install it, and then you're safe. But in this video I'm going to show you a website that also the backup has been infected with malware and logins... it is amazing. If you want to clean your WordPress website, we're going to start right now.

So on this dashboard I noticed something strange is going on. The client came to me with a question about some checkout that didn't work, but on logging in I saw this: 'WP Rocket could not modify the .htaccess file". This is not very normal. Also when I try to update this file, I go to a new tab and this is what I see: It is forbidden. This is not pretty normal. So the first thing I want to do is check the .htaccess about what's happening on this website. How you can do that? You can log in using FTP or you can log into your hosting company and there you can open up the file editor. So let's do that last one because it's most easy for everybody. Most hosting use Direct Admin some use Plesk as we have right here, and some others like Siteground they have their own backend. But what you need is you're looking for this: File manager. Now we're going to see about this .htaccess what's going on with this file, it is acting weird. This is strange, because normally when you open it, there is a way to edit it, like this one: "Edit in code editor'. When I do it with this one, it doesn't see that. Why? It has to do with the permissions I think, so let's see. All right the permissions has been changed so that we cannot write it. Let's put it on write and press save. Now let me see what's going on with this... now can we... yes now can we edit in the code editor. Okay let's see what happens. All right. This is not a normal WordPress .htaccess. So let me show you the normal .htaccess file in WordPress; is supposed to look like this. #Begin WordPress and #End WordPress and this is to make the rewrite rules good so you can use permalinks and all this kind of stuff. Um this is normal and this is what it says. It says order allow deny deny from all so what someone has been doing here, is all these files - those are not WordpPress files! Autoseo.php? Wp-block-header.php? Ms-sites? Those are not WordPress core files. So someone is trying to cover up, and trying to block us out to not edit these files. Right? We're gonna change this file back to the normal .htaccess file. So this is the normal one. We're going to copy it...

📖 Read the rest of the transcript at https://wpressdoctor.com/

#Hacked #WordPress #Malware #JapaneseSEOspam #cybersecurity


Watch video How To Fix Hacked WordPress Site & Malware Removal - Real live case online without registration, duration hours minute second in high quality. This video was added by user Matt - WPress Doctor 17 February 2022, don't forget to share it with your friends and acquaintances, it has been viewed on our site 51,67 once and liked it 1.1 thousand people.