Live case: irepairphone.es/blog. The client reported a “virus”. The home injected hidden betting spam (Premier League). Search users could see content the owner did not write.
This is rarely one infected plugin icon. Typical stack: a nulled or fake plugin, a theme file writing spam, extra admin users, and snippets in widgets or functions.php.
Cleanup that actually holds
- Inventory users, plugins and must-use plugins.
- Remove the fake plugin and any dropper files.
- Diff the theme against a clean copy; delete injected spam blocks.
- Rotate passwords, FTP and database. Check Search Console for hacked spam.
I do not claim “your site can never be hacked again”. I claim the visible spam and the known backdoor from this incident were removed, with a list of what to watch.