Scanning the files and the database
I compare the WordPress core, theme and plugin files with the original versions, and any difference is suspicious. In the database I look for scripts injected into content, settings and the users table. I replace infected files with clean copies from the original sources.