Cleaning up wordpress requires some professional knowledge. You need to recreate whole site with new wp-core, plugins, theme and just use old database to ensure you do not copy any old files.
After that install wordfence and monitor site.
If this is something more than you can handle, you should hire some professional sysadmin.
At this point stopping exim probably wonāt work as chance are high, that the attacker already took measure to restart or placed more executables on your system.
You did not run your page under the admin acount, right? RIGHT?
Make dumps of the process list and restart your server in rescue mode. Mount the disk and search for the infected files based on their names and timestamp.
Esp. if you have no experience get someone knowledgable to help you. Also rather reinstall the system and restore your pages from backups.
Disable everything (plugins, themes) in wordpress which you canāt exavtly say about who coded it and what it is doing.
I had suspended the user and the site. But now when I am trying to remove the suspension, it still says the site is suspended. Why is that? @Raphael@falzo
No idea, check the logfiles maybe? You most likely donāt want to reenable that page as it was anyway.
Rather deploy a new user and rebuild your page step by step as @mehargags alreadx mentioned.
It will lead you nowhere, if you donāt find what was causing the breach, it will simply happen againā¦
This will not help and is not needed. You need to clean your Wordpress site⦠not the whole server
Your site was inside isolated user and access of scripts / malicious items is still jailed to userās directory.
Resurrect your site from clean new updated WP-Core, plugins, theme and you should be good.
Scan your uploads folder for any scripts that might be malicious before copying to newly created site.
Restoring any files other that media in /uploads can lead to getting hacked/ infected again very soon.
Iām sorry, but this is not related to hestia itself. Please try to spin up some google searches about malware scan for wordpress, probaly wordfence and maldect is also an option.
find . -type f -name '*.php'
delete if you find any. You will need to go inside and browse through to see if you can get any other scripts that catch your eye.
There are many tools like Wordfence and other WP integrity checker tools that you can use⦠it is out of scope to discuss them here. Good luck
I searched in the forum about mod_sec and I got the impression that itās not very easy to get it working with Hestia. Especially for someone like me who does not know more than a few linux commands.
@attiqfsd Please keep us posted about the hack you suffered, particularly if there are any signs of āsystemic involvementā (i.e. any malware files outside of the WP userās home dir).