Short answer
Sort the File Manager by modification date: injected files almost always have a timestamp that does not match your last real change. Look especially for PHP files in upload folders, where no PHP file should ever be.
Learn more
- How to find malicious files on your websitePractical ways to spot injected and backdoor files: PHP where it shouldn’t be, recently modified files, obfuscated code and comparisons with clean copies.
- My website has been hacked: what to doThe signs a site is compromised and a clear recovery order: contain, preserve, restore or clean, close the hole, and check search engines.
- How to clean a hacked WordPress siteA step-by-step recovery for a compromised WordPress site: contain it, restore or clean, close the way in, and check it’s clean afterwards.
Step-by-step
- Recover a hacked websiteAdvanced · 120 min · 9 steps