Alright, this is a bit of an issue:
I recently got a job with an IT company (small business level), and they do a little bit of web development. Originally, the boss had a 3rd party freelance developer build a site for a major client. He was unhappy with his service, so he handed it down to me (managing the website, changing things, etc). I discovered that the website is blacklisted for spam, and that it's possibly what's called the "StealRat Botnet". I've done some reading, and found that it's usually found in the wp-content/plugins folder and/or in php files that shouldn't be there.
At home, I am on a Linux machine, so I am able to sftp into the server (also using Filezilla for GUI). Does anyone have any tips on how I can trace these corrupt files and get rid of this? I've tried sifting through files, but I don't know what I'm looking for. Any help is appreciated because this is a major issue.