wp-vcd.php Malware Removal: How to Eradicate the Self-Healing WordPress Backdoor
If your security scanner flags a file named wp-vcd.php or class.wp.php inside your /wp-includes/ directory, your server has encountered one of the most resilient self-healing infections in the WordPress ecosystem: the wp-vcd malware campaign.
This malware almost exclusively originates from "nulled" (pirated) premium themes and plugins downloaded from third-party distribution forums. Once executed, it does not stay inside the plugin you downloaded - it spreads laterally into every active and inactive theme on your hosting account.
Why Deleting the File Does Not Work
Most website owners locate wp-vcd.php and hit delete. Within 12 hours, the file is back.
Here is why: wp-vcd uses a distributed parent-child architecture. When the malware runs, it injects a small base64 loader into the functions.php file of every single theme installed on your server.
If you delete wp-includes/wp-vcd.php, the very next time a visitor loads any page on your website, WordPress executes functions.php. The injected hook notices that wp-vcd.php is missing, pulls the source code from its encoded payload, and recreates the file.
How to Tell If You Are Infected
- Rogue Admin Accounts: Users named
100010010,admin_backup, or random numeric handles appearing inwp_users. - Hidden Blackhat SEO Links: Injected footer links advertising pharmaceuticals or gambling that only render for non-administrative visitors.
- Google Search Console Penalties: Cloaked doorway pages detected across your domain index.
To permanently eradicate wp-vcd, you cannot clean individual files manually. You must simultaneously clean every theme's functions.php, replace the core wp-includes directory, and sanitize your database options.
If your site is currently infected and re-infecting itself daily, submit a Delvok rescue ticket and our engineers will disinfect the entire installation in under 4 hours.