Know your enemy

WordPress malware library: identify and remove

wp-vcd, lock360.php, webshells, cloaked injectors: each entry describes a real-world malware — files, symptoms, persistence and removal — straight from our cleanups.

Malware library

lock360.php: what this file is and how to remove it

Found a lock360.php file on your site? It's a backdoor. Here's what it does, where it hides and how to remove it without leaving a door open.

Read
Malware library

sc_, wp_custom_, home_links_custom_ options: spam hidden in wp_options

Spotted sc_, wp_custom_ or home_links_custom_ options in your wp_options table? That's database spam persistence. Here's how to identify and clean it.

Read
Malware library

Sky Login / redirect hijack: removing this fake plugin from WordPress

A 'Sky Login' plugin you never installed, and your site redirecting visitors? That's a redirect injection. Here's how to identify and remove it.

Read
Malware library

Vitrina Site Connector / SEO Client: the cloaked mu-plugins injector

A 'Vitrina Site Connector' or 'SEO Client' mu-plugin you never installed? It's an injector cloaking a casino redirect. Here's how to recognise and remove it.

Read
Malware library

wp-vcd: the nulled-theme malware and how to get rid of it

wp-vcd is one of the most widespread WordPress malwares, spread through nulled themes and plugins. Here's how to recognise it, remove it and stop it coming back.

Read
Malware library

WSO, FilesMan, c99: recognising and removing a WordPress web shell

A PHP file that shows a file manager in the browser? That's a web shell. Here's how to recognise WSO, FilesMan or c99 and remove them properly.

Read