We’re a small non-profit with a compromised website. I have two questions. Do I need to leave the tab open while the plugin runs?
It’s running right now but my other question is about what is scanned. Since we have multiple WP websites, our main site is in a folder in the root directory, so currently the anti-malware plugin is using this for the URL- OurURL.org/nameoffolder.
The problem is the evil script is nuking all .php files, and to restore the site I refresh WPress, but then I also have to replace the index.php and .htaccess file, both in the root directory above wordpress. Does this matter? Should I change the URL and drop the folder name?
thanks, will call the accountant tomorrow to kick in some donation.
Rudy
ps- I see this was asked about in 2013, maybe some changes were made? -R