Removing an infection properly.
THE ORDER
- Open a ticket so we can check the account server-side.
- Change every password: hosting, database, application administrators, FTP.
- Take a copy of the infected state before changing anything, in case you need it.
- Identify the extent: scan, check modified files, check for unknown accounts and cron jobs.
- Clean, preferably by restoring a backup from before the infection and then updating everything immediately.
- Without a clean backup: replace core files with fresh official copies, replace every extension with fresh downloads, remove anything unaccounted for.
- Close the entry point: update everything, remove nulled software, fix permissions.
- Request review if search engines flagged the site.
WHY CLEANUP FAILS
A missed backdoor The vulnerability not patched Credentials not all changed Malware on the owner's own computer supplying the new credentials
All four are common, and any one means reinfection within days.
AFTERWARDS
Monitor for a few weeks. Keep backups from before and after.