On this page
What malware cleanup involves
When a website or server is compromised, the visible symptom — a spam redirect, a defaced page, a browser warning, a hosting suspension — is usually only part of the picture. Attackers commonly leave backdoors: small, disguised scripts that let them return even after the visible damage is repaired. They may also add admin users, modify core files, insert code into the database or schedule tasks that re-infect the site.
Our malware cleanup service finds and removes all of that, then does the step that is most often skipped: identifying how the attacker got in and closing that route. Cleanup without root-cause analysis usually means being reinfected soon after.
Speed matters, but so does care. A rushed cleanup that deletes files without understanding them can break the site, destroy the evidence needed to find the entry point, or miss a second backdoor hidden elsewhere. We work quickly to stop the harm to your visitors, then methodically to make sure the job is finished properly.
Signs your site may be infected
- Visitors, especially on mobile or from search results, are redirected to unrelated sites.
- Search results show pages in foreign languages or for products you don’t sell.
- Browsers or search engines display a dangerous-site warning.
- Your hosting provider has suspended the account for malware or spam.
- The server is sending email you didn’t send, or running unusually slowly.
- Admin users or files appear that nobody on your team created.
This happens to all kinds of businesses: a clinic’s WordPress site with an outdated form plugin, an online store whose server was used to send spam, or a property portal where an upload form accepted a malicious file.
How we clean up, step by step
- Confirm authorisation — you own the site or have the owner’s written permission for us to work on it.
- Preserve evidence — take a copy of the infected site and relevant logs before changing anything, so the investigation isn’t destroyed by the cleanup.
- Contain — reset passwords and keys, remove unknown admin accounts, and where necessary put up a maintenance page.
- Find the infection — compare files against clean copies of the CMS and plugins, search for suspicious code and recently changed files, and check the database and scheduled tasks.
- Remove it — replace core files with clean versions, delete injected files and database entries, and remove backdoors.
- Find the entry point — review logs, versions and configuration to identify the most likely route in, such as a vulnerable plugin, a leaked password or an insecure upload.
- Close it — update or remove the vulnerable component, fix the configuration and harden access.
- Recover and monitor — take a fresh clean backup, request removal of blacklist warnings where applicable, and watch for signs of reinfection.
What you receive
- A cleaned website and server.
- A written summary of what was found, the likely entry point, and what was changed to close it.
- A verified clean backup taken after the cleanup.
- A period of monitoring for file changes and suspicious activity.
- Recommendations for preventing a repeat, prioritised by importance.
What affects timeline and cost
- How widespread the infection is — one site, or every site on a shared server.
- Whether clean backups from before the infection exist.
- How much custom code is involved, since custom files can’t be compared against an official clean copy.
- Whether logs are available to trace the entry point.
When a clean, recent backup exists and the entry point is clear, cleanup can be quick. Without backups or logs, more manual investigation is needed.
Common mistakes after an infection
- Restoring an old backup without fixing the vulnerability, so the site is reinfected the same way.
- Deleting the infected files before copying them, which removes the clues about how the attack happened.
- Changing the admin password but not database, hosting, FTP and API credentials.
- Cleaning one site on a shared server while the others remain infected.
Frequently asked questions
Can’t we just restore a backup?
Restoring a backup from before the infection can be part of the cleanup, but on its own it leaves the entry point open. The site is then likely to be compromised again the same way.
Will you get the search engine warning removed?
Once the site is clean, we request a review through the relevant search engine or security service where that option exists. The final decision and timing rest with them.
Do you clean sites on shared hosting?
Yes, as long as we have the access needed. On shared hosting we may be limited in what server-level logs are available, which we’ll tell you upfront.
How do we know the site is really clean?
We verify against clean copies of the software, re-scan after cleanup and monitor for file changes afterwards. No one can promise certainty, but monitoring means a missed trace is noticed quickly.
Should we take the site offline?
If the site is actively harming visitors, for example by redirecting them, a temporary maintenance page is usually the right call. We’ll advise based on what we find.
Talk to us about malware cleanup
Find the backdoor, remove the payload, and close the route it came in through.