Your site is almost definitely compromised. Doing your own cleanup may not be worth the time and effort because reinfection is likely if you miss a single infected file.
At this point I recommend to my clients that they get professional help. You may be able to get more details from a site scan by Sucuri. They have a free remote scan for virus infection.
Site scan by Sucuri
Related Posts:
- How to locate & delete hidden pages on a site
- how to reduce the number of spam comments
- A spam bot loves me, what can I do?
- Tips for finding SPAM links injected into the_content
- How to spam-filter a custom content type with the Akismet plugin?
- Getting trackback spam, even with trackbacks disabled
- How to block a someone from commenting?
- Reducing spammy user sign-ups
- How to reduce spam
- Hacked website redirect, only on desktop, help with restoring it [closed]
- How do I permanently disable Pingbacks?
- What are all these spam subscribers doing here?
- How to disable WordPress trackbacks?
- How can I delete all my existing trackbacks?
- How can I delete all users which have never commented / have posted spam comments?
- Comment Spammed vs Trashed
- Invisible spam post in backend
- Contact Form 7 being hijacked to send spam? [closed]
- How is my non-published blog getting so much spam?
- Contact Form 7 Plugin send emails to my Gmail as spam [closed]
- Automated spam being caught in 2 posts. Can this be used to help get rid of spam on everyone’s sites?
- WordPress Site has 35K spam images
- WordPress Phone Verification
- Is the tagline area spam-bot proof?
- Spam email sent from my [email protected] account
- How to block spam blocks pointing to a same website [closed]
- WordPress VPS out of Memory Problem
- Is it possible to determine proxy based comments?
- Spam Content Serving from old cached version of site?
- Subpage is redirecting to spam site
- How to track down a phantom contact form?
- How to get rid of spam forever?
- Spams, Scams on WordPress site – what to do?
- Auto block ALL IP’s indicated by Akismet?
- Simple comments spam solution
- How to stop people from using my domain to send spam? [duplicate]
- Why do I get comment spam even with Akismet and Captcha?
- Scanning Database for malicious Data
- How to remove comment spam in WordPress
- How is comment spam received without a comments form?
- How to prevent spam users registering even with registration disabled
- Number of External Links in Comments – Moderation Option
- Comments screen in backend, how to disable Quick Edit | Edit | History | Spam | for non admins
- Mass delete spam accounts
- Websites defaced by uploading script using theme editor
- How can I find security hole in my wordpress site?
- Has anyone experience w/ WordPress (MultiSite) hidden users (possibly hacked)?
- How to prevent bot or someone to modify any file automatically?
- How do i disable/disallow and tags in TinyMCE?
- Remove default user registration, login and subscriber profiles
- How to expire all wordpress user passwords instantly?
- Unfamiliar query string in Google Search Console URL not found
- Strange gibberish JavaScript in Editor – site hacked?
- wp-config.php modified?
- Suspicious Files
- 14,000 WordPress Users. How did they get there?
- Files automatically added
- sitemap contains weird links and does not contain my pages [closed]
- Malware script in database post table only? [closed]
- How do I programmatically set a user as spam in BuddyPress? [closed]
- New user is assigned 2 roles: customer and superadmin
- Hacked WordPress website /Homepage redirect [closed]
- Emails not getting delivered to Hotmail addresses
- How to find exploited wordpress plugin [closed]
- How to use a 3rd party library to send emails?
- Prevent Hacking of WordPress Site [closed]
- How to find a spam link?
- Troll the hackers by redirecting them
- reCaptcha doesnt appear in comment (manual or plugin)
- malware undetectable by multiple scans
- WordPress Hacked 5.5 admin-ajax.php [closed]
- Check for malicious code?
- Anonymous spam comments when only registered users can comment
- Replace domain in database
- Admin user lacks admin permissions after hack and can’t reinstate
- Is the current spate of hacks related to the recent security fix?
- Website Got Hacked – Fixed – Now Cannot Activate Theme
- Has anyone developed a anti-spam plugin to simply allow users to BLOCK whatever they wish to, but one that will also go easy on IP addresses?
- Why does my admin email address keep changing to something random?
- Javascript Injection on my WordPress Site
- Automatically reject a comment if website field contains anything
- malware in wordpress installer on dreamhost. [closed]
- Spam written by registred users
- Where I can find a list of WordPress security risks?
- Site has fake users registered with a similar pattern in username and email
- Comment moderation
- Hold a comment in the queue if it contains [X] or more links
- Prevent registration except through form
- Contact form spam, without form?
- Stop Authors from submitting spam post
- suspicious boolean.php file in wp web root [closed]
- How to remove content from hacked pages? [closed]
- My WP site and password was hacked, what to do? [closed]
- Should WordPress Add Options to Enhance Security or Leave it to plugin developers? [closed]
- How to hide and disable URL and email fields from comments?
- Redirected You too Many Times and Homepage Not Loading
- Dealing with HTTP w00tw00t attacks
- Strings of malicious code to look for after a hack
- WordPress website is redirecting on some different shopping page
- Hacked/cloaked sitemap [closed]