A website I do some volunteer work for was recently one of those affected by a wordpress plugin vulnerability.
Following advice in the answer to this question, which contains details of the attack, I am hoping someone can advise me on how to go about securing my website, since it is unknown to me if the script I posted about there managed to run itself before I killed it.
In particular, any information on how to go about ascertaining whether or not there is a SOCKS server active on the website would be appreciated (and how to kill it, if there is). I am fairly new to the behind-the-scenes aspect of websites, as you may be able to tell. If any other information is needed, for example the tools provided by my host, please let me know.
EDIT: this is not the same as the questions marked as similar, since those are general questions about how to secure a server. While I will take the advice in those questions, I am interested here specifically in how to find a kill the specific manifestation of the malware on my server - a SOCKS server.