Mark RauterkusTips

Could this be true

2026-05-20 · Status: publish · Development, Hardware, Pair

Hi, Subject: Current plan and question about possible control-panel-level activity Hi Don, Thank you for the detailed options. For now, I am going to keep working inside the existing rauterkus1 account and continue cleaning the active sites and pages. I am not ready to launch the temporary second server yet, but I do like the idea of moving public_html out of the way and rebuilding from a clean public_html as a possible next step. That may be something we want to do next week after we stabilize the most important sites. For the second-server option, if we go that route, please assume PHP 8.4. For MySQL, I do not see a reason to use an older version. These are WordPress sites, so I would prefer a current, stable MySQL/MariaDB version that Pair recommends for modern WordPress compatibility. One thing I want to flag: I have now heard from two independent sources that similar reinfection patterns may be happening at a broader hosting/control-panel layer, not just inside one WordPress site. I am not claiming that is confirmed here, but the behavior has been odd. Files that were cleaned or hardened have later reappeared or changed again, including .htaccess, index.php, robots/sitemap files, and Google verification files. Have you seen any other customers reporting similar repeated reinfections, especially involving: Google Search Console ownership injection Google verification HTML files appearing unexpectedly .htaccess disappearing or being rewritten index.php bot-cloaking code being reinserted malicious PHP files writing new .htaccess rules malware targeting multiple WordPress installs under the same account shell-like behavior even without normal SSH access I understand from your earlier note that PHP web shells are the likely path. My concern is whether something is still running somewhere under the account, or whether there is any broader issue at the account/control-panel/web-server layer that would explain the repeated reappearances. At this point, I would appreciate Pair’s help watching for any active process, cron job, hidden PHP execution, or server-side mechanism that may still be writing files after cleanup. Current plan on my side: Keep cleaning infected WordPress sites. Replace hacked core files with clean WordPress files. Remove suspicious files and unknown Google verification files. Rotate WordPress admin passwords. Rotate database passwords after each site is stabilized. Refresh salts. Keep Wordfence scanning active. Consider the clean public_html rebuild approach next week. Please let me know whether Pair sees anything still actively executing under rauterkus1, and whether you recommend we move forward with the public_html_Comp plan sooner rather than later. Thanks, My boss may hire a consultant for 3-months for site monitor and small updates. I'm fine with that to get him peace of mind.

Source: helpdesk.WordPress.2026-06-05.xml · Original ID: 4930