URL is hijacked

Hello,
I noticed today that when I search for the term “fire island webcam” my website, palmshotelfireisland.com comes up 3rd and the title has been changed to " Dapoxetine - Palms Hotel …" and then you get taken to a drug company. I looked at the source code and its been rewritten with all their junk, as shown below. What file do I go into in order to remove this and how do I prevent it from happening??

TIA!
Rena

**Dapoxetine >> Dapoxetine without prescription. Brand and Generics - Official Canadian Pharmacy**

Update: GoDaddy seems to have fixed this for me. But if you can still tell me how I would fix it in case it happens in the future Id apprecaite it!
Thanks
Rena

Ignore that, they didnt fix it : (

Hi Rena,

Please try testing for a plugin conflict. You can do this by deactivating all third party plugins, and seeing if the problem remains. If it’s fixed, you’ll know a plugin caused the problem, and you can narrow down which one by reactivating them one at a time.

If you are still getting the issue on your site, try installing the Wordfence plugin then scan the files of your site.

In case you’re not able to find the cause of the issue, please provide us with the admin and FTP details of your site in a secure note so that we could check your site.

I have deactivated all plugins but its still bringing to a pharmacy website. I have noticed it does bring me to my website in chrome and only brings me to the pharmacy in Safari.

However in Chrome the title tag does have a pharmacy drug name in it.

Also when I view the source code in Chrome its fine, when i view the source code in Google search console its all about the pharmacy.

I have ran wordfence and it came back as one possible malware file. I opened it and dont see anything wierd.

Hello @fatcatgraphics,

Thanks for updating the thread.

Can you please share WordPress admin details in secure note for us to take a closer look?

Thanks.

Ok thank you, I added it to the secure form above.

Hi Rena,

It seems that your website has a compromised file that is displayed in the Wordfence scan result:

The file mentioned is not part of the Wordpress core and the plugin where it is in and the code in the file looks suspicious.

Kindly try downloading the file and deleting from its location and do further checking on your site. In case you delete the file but it gets restored by itself, it could be that your site was hacked.

Please check this thread for some information:

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.