Shafail Shafa

← All case studies

WordPress · 2024 · Fiverr

Two infected sites on one hosting account

A site had started sending spam. I cleaned it, kept everything I pulled out instead of deleting it, and then found a second site on the same account with the same infection. Both done inside two days.

The objective

The client resells web work, and the site belonged to one of their own customers. It was sending spam, which usually means the mail is going out through the site itself rather than a mailbox. That points at a compromised account, not a guessed email password.

The client asked a good question early: should the mail password be changed as well? On a site that's been sending spam, yes, along with everything else the site touches.

What I did

I cleaned the infection and reset the WordPress logins.

Everything I pulled out went into a separate folder instead of the bin, and I told the client to hang onto it for now. Their customer's own plugin-generated backups were sitting in that folder, and deleting it outright would have taken the backups with it.

I ran a full security scan afterwards and stayed with it until it finished, rather than handing back a site with a scan still going.

I spelled out what to do next in plain terms: make sure the scanner is emailing its alerts to an address somebody actually reads, and act on what it finds instead of letting it pile up.

When a second site on the same account turned out to have the same infection, I checked there was free space in the account before I started and cleaned that one the same day.

The result

Both sites came back clean inside the two days the client had, and the files I'd removed stayed put long enough for them to confirm nothing was missing.

“Great Job...!! I needed 2 tasks done within 48 hours and all was completed on time and on budget. Thank for your professionalism, I'll be back...!!”

Fiverr client, Canada, 2024