Your site is almost definitely compromised. Doing your own cleanup may not be worth the time and effort because reinfection is likely if you miss a single infected file.
At this point I recommend to my clients that they get professional help. You may be able to get more details from a site scan by Sucuri. They have a free remote scan for virus infection.
Site scan by Sucuri
Related Posts:
- How to locate & delete hidden pages on a site
- how to reduce the number of spam comments
- A spam bot loves me, what can I do?
- Tips for finding SPAM links injected into the_content
- How to spam-filter a custom content type with the Akismet plugin?
- Getting trackback spam, even with trackbacks disabled
- How to block a someone from commenting?
- Reducing spammy user sign-ups
- How to reduce spam
- Hacked website redirect, only on desktop, help with restoring it [closed]
- How do I permanently disable Pingbacks?
- What are all these spam subscribers doing here?
- How to disable WordPress trackbacks?
- How can I delete all my existing trackbacks?
- How can I delete all users which have never commented / have posted spam comments?
- Comment Spammed vs Trashed
- Invisible spam post in backend
- Contact Form 7 being hijacked to send spam? [closed]
- How is my non-published blog getting so much spam?
- Contact Form 7 Plugin send emails to my Gmail as spam [closed]
- Automated spam being caught in 2 posts. Can this be used to help get rid of spam on everyone’s sites?
- WordPress Site has 35K spam images
- WordPress Phone Verification
- Is the tagline area spam-bot proof?
- Spam email sent from my [email protected] account
- How to block spam blocks pointing to a same website [closed]
- WordPress VPS out of Memory Problem
- Is it possible to determine proxy based comments?
- Spam Content Serving from old cached version of site?
- Subpage is redirecting to spam site
- How to track down a phantom contact form?
- How to get rid of spam forever?
- Spams, Scams on WordPress site – what to do?
- Auto block ALL IP’s indicated by Akismet?
- Simple comments spam solution
- How to stop people from using my domain to send spam? [duplicate]
- how to trash WordPress comments if its not in English
- WordPress and wamp sending “Delivery status notification Failure” to my inbox every 7 minutes
- Verifying that I have fully removed a WordPress hack?
- Why do I get comment spam even with Akismet and Captcha?
- If a hacker changed the blog_charset to UTF-7 does that make WordPress vulnerable to further attacks?
- Removing the “Website” Field from Comments and Replies?
- WordPress site hacked. Has .htaccess been hacked?
- Experiences with adding Nonces to the comment form
- Scanning Database for malicious Data
- How to deal with small scale comment spam on small commercial sites? [closed]
- What methods should be used to fend off splogs in a multiuser install? [closed]
- What’s the easiest way to close comments on media/attachments?
- How to remove comment spam in WordPress
- How is comment spam received without a comments form?
- How Attackers write script into my php files?
- Local wordpress setup with SPAM in the incoming links dashboard section?
- How to prevent spam users registering even with registration disabled
- Allow anonymous comments, but prevent spam [closed]
- Is this a hacking script in function.php?
- How exactly does Bad Behavior plugin work?
- Is there any advantage to emptying comment spam?
- Why do I get email notifications about comments that WordPress has already determined are spam?
- Number of External Links in Comments – Moderation Option
- Comments screen in backend, how to disable Quick Edit | Edit | History | Spam | for non admins
- Check spam in custom form – akismet
- What should I do about hacked server?
- Mass delete spam accounts
- Websites defaced by uploading script using theme editor
- What’s the effect if this malware if infected your WP?
- What is the best way to avoid spammers registering to my blog?
- How can I find security hole in my wordpress site?
- Malware on site [closed]
- What do spammers gain by signing up as a user?
- Strategies for coping with hyperagressive spambots?
- Has anyone experience w/ WordPress (MultiSite) hidden users (possibly hacked)?
- Restrict access to xmlrpc.php
- Website is being flooded [closed]
- How to find the backdoor of the hack
- How Do I Prevent Junk Account Creation?
- How to prevent bot or someone to modify any file automatically?
- My wordpress site was hacked – is my htaccess file compromised?
- Akismet plugin is deleting spam despite preferences
- My WordPress Blog sends malicious traffic to other sites [closed]
- How do i disable/disallow and tags in TinyMCE?
- How can I automatically delete comments that contain chinese / russian signs?
- Comments view limited to 20 results – any way to increase to 50 or 100?
- Something is generating spam pages on my site
- Hacked WordPress website, as notified by Google Search Console, what to do? [closed]
- Remove default user registration, login and subscriber profiles
- How to expire all wordpress user passwords instantly?
- Buddypress Fake (non-bot) Users [closed]
- New users must comment when requesting username
- Change WP-Login or WP-Admin
- Report spam button
- hSite has no css on mobile [closed]
- wp_redirection_404 table has grown to 7GB
- How to mass delete one line from all posts after site hack
- How was my WP site hacked [closed]
- Unfamiliar query string in Google Search Console URL not found
- Strange gibberish JavaScript in Editor – site hacked?
- wp-config.php modified?
- How to bulk delete all WordPress subscribers?
- Bots posting comments on pages
- Security issues with WP sites