Skip to content
WP Hack FixEst. 2005

A security plugin says I'm infected but I can't remove it

A scanner telling you there's malware, offering a repair button that doesn't help, and then reporting the same thing tomorrow is a frustrating place to be. Scanners are genuinely useful, but they're built to notice problems, not to resolve them. Knowing what a scan result can and can't tell you is usually the difference between chasing the same alert for a week and actually fixing the site.

We reply within 1 business day (Mon–Fri, 9–5 ET)

What you're seeing

  • Scan results that come back after you click "repair" or "delete"
  • Files the scanner flags but says it can't fix automatically, often in a plugin or theme rather than in WordPress core
  • Warnings about "unknown files in core", or files that don't match the official WordPress versions
  • A flagged file you're afraid to delete because you don't know whether the site needs it
  • Your host's scanner and your security plugin disagreeing about whether the site is infected
  • A clean scan that you don't quite believe, because the site is still behaving strangely

Why it happens

Core repair doesn't reach most infections

The "repair" or "restore original file" option compares your WordPress core files with the official versions and replaces them. That works for core, and does nothing for infected plugins, themes, uploads, or code stored in the database, which is where most malware lives.

The backdoor is putting it back

If the same file reappears after deletion, something is recreating it: a backdoor, a scheduled task, or a must-use plugin. Deleting the visible file is treating a symptom on a loop.

Scanners match known patterns

Most scanning works by comparing files against signatures of malware that has been seen before. A freshly written or heavily obfuscated backdoor can score completely clean, so a clean scan is reassurance rather than proof.

False positives are real

Legitimate plugins sometimes use techniques that look suspicious to a scanner, and premium or custom code is flagged more often than most. Deleting a flagged file without checking can break the site, so it's worth confirming what a file actually is first.

The scan covers less than you think

Some scanners only check files, not the database. Others skip large directories or stop early on big sites, so content outside the scanned area is never examined at all.

What to do right now

Do this

  • Export or screenshot the full scan results, including file paths and dates. That list is the starting point for a proper cleanup
  • Take a backup of the current state before deleting anything, so nothing is lost if a flagged file turns out to be legitimate
  • Check the flagged file's date against your own activity. A file changed at 3am on a day you didn't touch the site tells you a lot
  • Look beyond the scanner: administrator accounts you don't recognize, scheduled tasks, and the must-use plugins folder

Don't do this

  • Don't mass-delete everything flagged. Some of it may be legitimate code your site needs, and deleting it can take the site offline
  • Don't treat a clean scan as an all-clear if the site is still misbehaving. Signature scanning misses new backdoors
  • Don't reinstall WordPress core as a fix. It replaces core files only, and most infections aren't in core

How we fix it

  1. 1Work through the scan results with you and separate genuine infections from false positives, so nothing legitimate gets deleted
  2. 2Inspect the site by hand as well as by scanner: plugin and theme files, uploads, the database, .htaccess, scheduled tasks, and must-use plugins
  3. 3Clean each infected file properly rather than deleting it blindly, repairing the ones your site actually needs
  4. 4Find the backdoor and the entry point that's causing the results to reappear, and remove rogue accounts and tasks
  5. 5Update and harden the site, then re-scan and give you a written report of what was found and what was done

Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing

Questions

My scanner says it can't repair the file. What does that mean?

Usually that the file isn't part of WordPress core. Repair works by comparing against the official WordPress files and restoring the original, which is only possible for core. For an infected plugin, theme, or uploaded file there's no original to compare against, so the scanner can flag it and stop there. Those files need to be cleaned or replaced deliberately, which is the manual part of the job.

Could it be a false positive?

It genuinely could, and it's worth checking rather than assuming either way. Some legitimate plugins use code patterns that scanners treat as suspicious, and custom or premium code gets flagged more often. Checking what the file is and where it came from takes far less time than recovering from deleting something your site needed.

The scan is clean now. Am I definitely fine?

A clean scan is good news, but it isn't a guarantee. Scanners match patterns from malware that has already been cataloged, so a new or well-hidden backdoor can pass. If the site is still redirecting, sending spam, or showing up oddly in Google after a clean scan, the scanner is missing something and the site needs looking at by hand.

Other symptoms

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)