Today I got new case for clean up wordpress malware, I love this job since I have a chance to see new hosting company system and how they work. Web hosting my client use is Godaddy.
I prefer to use ssh and Godaddy provide it with easy to activate interface, I use ssh since their file manager not fit for my 10 inch netbook and their ftp java also not help me a lot for doing my job.
As usual, scan for base64 hidden code and checking .htaccess give me clue where the bad code reside. Cross check it using sucuri scanner and dump lynx result with my vps server . Everything is ok.
After a few minutes I recheck with semrush on how it goes on search engine and try to open it straight from google result. Ooops, the malware seem to go back and redirect traffic to their website (a russia domain).
