my site has had a report of malware

Hi, apparently the new site has malware, I have had trouble with this site from before I was able to download wordpress. What can I do about it please?

  • Ana

    Additional information the report reads

    up.php
    /home/sites/6b/5/5e902d9d35/backup/wp-content/plugins/matamu/up.php

    galek.php
    /home/sites/6b/5/5e902d9d35/backup/wp-content/plugins/matamu/galek.php

    I have no idea what this means but it looks like it is connected to the wordpress backup plugin that was downloaded from your site. Am I right about this and how do I fix it please?

    Thanks

  • Nastia

    Hello Ana

    Hope you're doing well!

    The malware is coming from the Mata HOYGAN plugin. This is a very old plugin and has not been updated in a while. Old plugins can be easily compromised. If this plugin is still installed on your site, I suggest removing/replacing this plugin with another one to remove the malware and for security reasons.

    The infected file is located in the /backup/ folder but it is not related to our Snapshot - backup plugin. The /backup/ folder was either created manually or by another plugin. The Snapshot plugin keeps the backup file in a different folder in
    public_html/wp-content/uploads/snapshots/

    To remove the malware please remove the /matamu/ folder from the backup folder:
    /backup/wp-content/plugins/matamu/

    If you need assistance removing this folder please send to us your FTP credentials, we will remove it for you. You can send credentials by using our secure contact form
    https://premium.wpmudev.org/contact/#i-have-a-different-question

    Subject: “Attn: Nastia”
    - WordPress admin username
    - WordPress admin password
    - Login URL
    - FTP credentials (host/username/password)
    - Link back to this thread for reference
    - Any other relevant URLs

    To harden the security of your site , please try out the Defender plugin. Scan your site and apply the security tweaks from Defender > Security Tweaks.

    Let us know how it went!

    Kind regards,
    Nastia

Thank NAME, for their help.

Let NAME know exactly why they deserved these points.

Gift a custom amount of points.