Note: Please ensure to back up website before doing anything
- Check all the infected files and remove them from the cpanel.
- Check CMS side of the website, if there are unexpected plugins/modules as code added.
- Check the registered users and confirm them with clients. Delete the unknown users account.
- Change admin username and password for CMS.
- Check all the payments methods and confirm them with client for each payment method (PayPal, Eway etc.)
- Remove additional URL’s from WordPress in CMS side.
- Check cpanel/unders and emails also add forwarded emails and confirm with client.
- Change the CMS access URL eg. /admin etc.
- Keep checking front-end impact on website.
- Keep focusing on URL’s re-directs.