Hi there,
I’ve used your plugin to resolve a backdoor and remove known infected files. I notice that there are still some folders left on my server that are spammy.
The folder is hidden in the wp-content folder, called .st (and a hidden file called .bt) and the folder contains 37 heap of .txt files named like:
domain.com|?uvw=%E0%B8%95%E0%B8%B1%E0%B8%A7%E0%B9%80%E0%B8%A5%E0%B8%B7%E0%B8%AD%E0%B8%81%E0%B9%84%E0%B8%9A%E0%B8%99%E0%B8%B2%E0%B8%A3%E0%B8%B5&9d9=fe.txt
I can’t manually remove these from my server using FTP software, as I don’t have permission. When I try and remove through the File Manager in my hosting console, they don’t even show up.
There is probably a setting in your File Manager to show hidden files, but if the permissions are locked down then it may not help anyway.
You may need to get your hosting providers help with elevated privileges so that they can remove those directories for you.