Alright, this is a bit of an issue:
I recently got a job with an IT company (small business level), and they do a little bit of web development. Originally, the boss had a 3rd party freelance developer build a site for a major client. He was unhappy with his service, so he handed it down to me (managing the website, changing things, etc). I discovered that the website is blacklisted for spam, and that it's possibly what's called the "StealRat Botnet". I've done some reading, and found that it's usually found in the wp-content/plugins folder and/or in php files that shouldn't be there.
At home, I am on a Linux machine, so I am able to sftp into the server (also using Filezilla for GUI). Does anyone have any tips on how I can trace these corrupt files and get rid of this? I've tried sifting through files, but I don't know what I'm looking for. Any help is appreciated because this is a major issue.
Most of the corrupted WordPress websites are due to malicious themes and/or plugins.
Try searching for each occurence of
exec(base64_decode(andeval((as those are the most common snippets hidden in malicious files) in your php files in both your wp-content/themes and wp-content/plugins directories, that should be a good start.If you know when the website has been infected, you could also try to look for files edited or added around that time (easy to do in SSH if you have access to the server)
Good luck to you, I recently had to clean several WordPress sites, this wasn't a cake walk.