Malware removal and hardening

WordPress Malware Removal: clean the hack and stop it coming back.

A hacked WordPress site needs more than deleting the most visible malicious file. This is emergency WordPress malware removal done as incident response: the engagement investigates the extent of compromise, removes malicious persistence, restores trusted components, and reduces the likelihood of reinfection — with a reply within 24 hours and most single-site cleanups finished in 1–3 business days.

Never send credentials, private keys, backup archives, or confidential source code through this website.

Best for
Redirects, spam, backdoors, rogue users, host suspensions, or repeat infection
Priority
Containment and safe restoration before cosmetic cleanup
Coverage
WordPress files, database content, accounts, persistence, and relevant logs
Output
Cleanup record, likely entry conditions, hardening actions, and verification
Typical fee
$120–$500 per site · most single-site cleanups finish in 1–3 business days

Warning signs

When to treat the problem as an incident

Unexpected redirects

The site is redirecting to spam, another site, fake updates, gambling, pharmacy, or credential-harvesting pages — often only for mobile visitors or people arriving from Google, so the owner sees nothing.

Search spam

Japanese characters or unknown pages appear in your Google results, cloaked content is served to crawlers, or Search Console reports pages you never created.

Fake verification pages

Visitors see a fake CAPTCHA, Cloudflare-style check, or “verification step” asking them to paste a command — the ClickFix pattern documented in our incident report.

Unknown access

A new administrator account you did not create, changed credentials, unfamiliar SSH or control-panel users, or unexplained scheduled tasks appear.

Recurring infection

Malware keeps coming back after a plugin scan, restore, or prior cleanup — the sign of surviving persistence or an unclosed entry path.

Browser, search, or host warnings

Chrome shows “Deceptive site ahead”, Google labels the result “This site may be hacked”, or the hosting provider suspends the account.

The first 30 minutes

What to do — and not do — before any cleanup starts

The first reaction to a hacked site often destroys the evidence needed to stop the next infection. These steps limit harm without burning the trail.

  1. 01

    Do not run anything the site tells you to

    If any page asks you to open a Run dialog, terminal, or PowerShell and paste a command, close it. That instruction is aimed at infecting your computer, not fixing the site.

  2. 02

    Preserve before you delete

    Keep the current state: leave existing backups untouched, and note file timestamps if you can. Deleting “suspicious” files first removes the clues that identify the entry path.

  3. 03

    Record what you see

    Screenshot the symptom, copy the affected URLs, and note when it started, who reported it, and any host or browser warning. Investigators need this context verbatim.

  4. 04

    Work from a clean device

    Use a computer you trust for anything administrative. If an administrator laptop may be compromised, fixing the website first solves the wrong problem.

  5. 05

    Rotate critical credentials from that clean device

    Change hosting-panel, WordPress admin, and database passwords — but keep a record of what you rotated and when, so access changes are distinguishable from attacker activity.

  6. 06

    Do not restore a backup yet

    A backup taken after the compromise restores the malware; restoring before the entry path is closed recreates the incident. Confirm the backup is clean first.

Why it comes back

Deleting one file rarely ends the infection

Modern WordPress malware persists in several places at once — files, database records, the active theme, PHP configuration, and sometimes the hosting account itself. Removing the visible symptom while any layer survives restarts the loop.

Why the infection appears to come back

  1. 01

    A scan finds one bad file

    The visible symptom is identified.

  2. 02

    Only that file is deleted

    The page may look normal for a while.

  3. 03

    Another layer survives

    The database, theme, .user.ini, or attacker access remains.

  4. 04

    The infection returns

    A later request, restart, cache refresh, or deployment loads it again.

Response process

From triage to a verified clean state

  1. 01

    Triage and preserve

    Confirm symptoms, establish safe access, capture relevant evidence, and avoid destroying useful incident context.

  2. 02

    Contain and investigate

    Limit active harm, inspect files, database records, users, scheduled tasks, logs, and common persistence locations.

  3. 03

    Clean and restore

    Remove malicious artifacts, replace untrusted components from known-good sources, rotate affected access, and repair altered content.

  4. 04

    Harden and verify

    Address the likely enabling conditions, review the site again, and document remaining risks or host-owned actions.

Included work

Cleanup covers more than the plugins screen

  • Core, plugin, theme, upload, configuration, and mu-plugin integrity review
  • Database inspection for injected content, accounts, options, and persistence
  • Backdoor and scheduled-task review within the authorized environment
  • Administrator, hosting, deployment, and relevant credential review
  • Vulnerable or abandoned component assessment
  • Post-clean hardening and a documented verification pass
  • Guidance for blacklist or hosting-review requests when applicable

Boundaries

What determines whether the site can stay clean

No responsible provider can promise that a site will never be compromised again. The result depends on whether every affected account and neighboring environment is within scope, whether the host supplies necessary logs and isolation, and whether vulnerable components can be patched or replaced.

A repeatedly reinfected site may indicate a compromised hosting account, another infected site under the same account, an exposed deployment credential, or persistence outside the WordPress directory. Those dependencies are identified during scoping rather than hidden behind a cleanup guarantee.

Common questions

Questions about this engagement

Should I restore the latest backup immediately?

Not before confirming that the backup is clean and preserving useful evidence. Restoring an already compromised backup or leaving the entry condition unchanged can recreate the incident.

Can you remove Google or browser warnings?

The site can be cleaned and prepared for the relevant review process. Removal of a third-party warning is controlled by that provider and cannot be guaranteed.

Will the site need to go offline?

It depends on the active harm and environment. Containment options and availability constraints are agreed during triage.

What should I send in the first message?

Send the domain, symptoms, when they began, any host or browser warning, and business impact. Do not send credentials, private keys, or backup archives by email or through the website.

Will the hack hurt my SEO rankings?

It can — injected spam pages, redirects, and Safe Browsing warnings all affect how Google treats the site. Most ranking damage recovers after a verified cleanup, removal of injected content, and reindexing, but the timeline depends on how long the infection served spam and whether warnings were issued.

Do you work directly with my hosting provider?

Yes, where the host cooperates. Some evidence — server logs, account-level isolation, suspension reviews — is only available from the provider, and host-owned actions are identified in the report rather than silently skipped.

How much does WordPress malware removal cost?

Typically $120–$500 for a single infected site, with most single-site cleanups completed in 1–3 business days. Multi-site fleets, missing hosting access, and repeat-reinfection investigations are scoped individually, and the proposal states the exact fee before work begins.