Hacked website cleanup and recovery
Redirects to unknown sites, spam pages in search results, an email from your host. We clean up, close the entry point and lift the warnings.
What's included
- Diagnosis and forensic snapshot
- Malicious code removal
- Entry point identified and closed
- Backdoor hunting
- Credential and key rotation
- Search engine warning removal
- Written report and next steps
If you're reading this in a panic, take a breath first. An infected site is recoverable, the data is usually intact, and while the situation is unpleasant it is entirely workable. Compromise shows itself in several ways: visitors get redirected to somewhere unfamiliar, search results fill with pages about products you don't sell, the browser flags your site as dangerous, your host emails about outbound spam, or traffic suddenly spikes for no reason.
The key thing to understand is that deleting the malicious file you found is not a cleanup. Unless you establish how it got uploaded, it returns within days. So the work has two halves: remove the consequences and close the cause. The second half matters more and takes longer, even though it produces nothing visible.
How we work
- Diagnosis and snapshot. We take a complete image of the site and database in its current state, before changing anything. It serves both the investigation and as a safety net if cleanup goes sideways.
- Assess the scope. We compare files against clean engine releases to find modified and extra ones, inspect the database for injected scripts, and read the access logs.
- Cleanup. We remove malicious code from files and database. Carefully, because infections are often woven into working code and blunt deletion breaks the site.
- Find the entry point. From the logs we reconstruct how they got in: a vulnerable plugin, stolen FTP credentials, an unguarded upload form, or a neighbouring site on the same hosting account.
- Hunt for backdoors. Separate work, and essential. Attackers leave hidden ways back in, and those can sit for months inside files that look entirely innocent.
- Rotate access and lift warnings. All passwords and keys change, vulnerable software gets updated, and the site is submitted for re-review to search engines and antivirus databases.
What you get
A clean site, a closed hole, and a clear account of what happened. The report covers how they got in, what they did, what changed, and which areas remain weak. Plus the removal of browser and search engine warnings, which typically cost more traffic than the compromise itself.
An honest limitation: when an infection runs deep and malicious code is interwoven with legitimate code beyond separation, rebuilding on a clean installation and migrating the content is often faster and safer. We'll say so directly rather than spending weeks scrubbing something hopeless. To stop this recurring you need ongoing attention afterwards — technical support with updates and monitoring. For the most commonly targeted platform there's a dedicated page: WordPress support.
Timeline
Diagnosis happens the day you contact us. Cleaning a typical infection on a small site takes one to three days. Complex cases — several sites compromised on shared hosting, or malware that has been resident for months — take longer. Getting search engine warnings lifted is no longer in our hands: re-review runs from a few days to a couple of weeks. We quote after diagnosis, because before it the scope is genuinely unknown.
A typical scenario
Here's a common shape: the owner notices the site redirects mobile visitors to an unrelated destination while everything looks normal on desktop — a standard trick to delay discovery. Investigation shows entry came through an abandoned plugin with a published vulnerability, and the malicious code was distributed across several theme files plus one database record. Restoring from backup wouldn't help here: month-old copies are already infected, because the malware had been resident far longer than the owner assumed.