WordPress · Security

Malware removal for WordPress websites

An infected website is usually recognised by its effects: visitors from Google end up on someone else’s website, the browser shows a red warning page and emails from the company domain start landing in spam. Cleaning the files, however, is only half of the work. The other half is finding the way in and closing it.

  • Most jobs done within 24 hours
  • 30-day guarantee: free removal if the infection returns
  • Report listing every change
  • Request to lift Google warnings

Scope of work

What I do on an infected website

I analyse each infection individually, but I always follow the security procedures in the same order, and they are what ensures that the infection does not come back. The last item is worth the most: the report, which tells you what actually happened.

Scanning the files and the database

I compare the WordPress core, theme and plugin files with the original versions, and any difference is suspicious. In the database I look for scripts injected into content, settings and the users table. I replace infected files with clean copies from the original sources.

Removing the malicious code

I remove redirects that send visitors from Google to other websites, hidden spam pages, scripts added to theme files and cron jobs that restart the infection. The folders outside WordPress are part of the check as well, because an infection rarely stays in one place.

Closing the way in

Removing the malware without closing the security hole means the problem returns within a few days. I establish how the attack happened, whether through a vulnerable plugin, a weak password or a hijacked FTP account. Then I update or remove the vulnerable component and change all passwords and authentication keys.

Google warnings and spam blacklists

When Google marks a domain as dangerous, browsers show a red warning page and emails from your domain land in spam. After the clean-up I submit a review request in Search Console and handle the removal from spam blacklists.

Hardening the website

I limit login attempts, block PHP from running in the uploads folder and tidy up file permissions and administrator accounts. On top of that comes a proven security plugin, and in more serious cases a web application firewall.

A report of what I found

You get a list of the infected files, a description of the injected code, the way the attacker got in and a list of the security measures I put in place. The same document helps if you have to report the incident to someone or explain it to your customers.

The most serious case I have handled was an online shop with a planted administrator account and a script that captured card details on the payment page. You can read about it, without the client’s name, in the case study.

Process

How I remove an infection

The removal costs €500 net for a WordPress website and €900 net for a WooCommerce shop, and the price covers the whole process below. Whether the result lasts depends on the middle step: if I do not find the way in, the infection comes back within a few days.

  1. A copy before the clean-up

    Before I remove anything, I copy the infected website and the database. That copy protects you in case the clean-up removes something the website needs.

  2. Clean-up and finding the way in

    I replace the infected files, clean the database and check the administrator accounts and cron jobs. At the same time I read the server access logs, which show when and how the attack happened. Without this step, a clean-up only postpones the problem.

  3. Hardening and return to normal

    I update the vulnerable components, change the passwords and keys, harden the configuration and then request the removal of the warnings. Over the following days I watch the website for any sign of the infection returning, and only then do I close the job.

All prices are net, excluding VAT. The offer is for businesses only.

Starting the clean-up

What I need from you

With an infection, time matters, because the sooner I have access, the fewer visitors see the warning. The WordPress admin panel alone is usually not enough.

After the clean-up, change all your passwords, including those you use elsewhere. Whoever had access to the files could read the login details stored in the WordPress configuration file.

  • a WordPress administrator account, and FTP or SSH access if the admin panel has been taken over
  • login details for the hosting control panel, because the access and error logs matter most in this work
  • access to the database (phpMyAdmin or SSH)
  • access to Google Search Console, if the domain already shows a warning
  • information on who has administrator accounts and when the first symptoms appeared

Other services

Cleaning up a website after a break-in only makes sense if someone keeps it updated afterwards. These three services most often go together with malware removal.

All case studies

If the website is slow or shows errors after the infection, see WordPress speed optimisation as well. All WordPress services are on the WordPress page.

FAQ

Questions about malware removal

What website owners ask in the first hour after they discover the problem.

How long does the clean-up take?

I finish most jobs within 24 hours of receiving access. It takes longer when the infection has spread to the database, cron jobs and folders outside WordPress, or when several websites on one hosting account are infected. The work can then take up to 3 working days. You get the timeline after the first scan, before the clean-up starts.

How much does WordPress malware removal cost?

Removing an infection costs €500 net for a WordPress website and €900 net for a WooCommerce shop, however many files need replacing. The price also includes closing the security hole the attacker used and a 30-day guarantee: if the infection returns within that time, I remove it free of charge. All prices are net, excluding VAT. The offer is for businesses only.

How can you be sure the infection will not come back?

Because besides removing the code, I close the way in. That means updating or removing the vulnerable component, changing all passwords and authentication keys and tidying up the administrator accounts. I give a 30-day guarantee on the clean-up: if the infection returns within that time, I remove it free of charge.

Will Google remove the warning straight after the clean-up?

Not automatically. After the clean-up I submit a review request in Search Console, and Google usually checks the website within 24 to 72 hours. Removal from spam blacklists can take longer, and the domain’s email reputation needs a few more days to recover. So it is best not to plan a large email campaign right after an incident.

The infection affected customer data. What now?

You get a technical report showing which files were infected, what code they contained, since when it was active and what it had access to. That is the material you need to assess the scale of the incident. Reporting a personal data breach to the data protection authority can be mandatory, with a short deadline. I do not make a legal assessment, but I tell you when a case looks like a breach.

What access do you need to start?

A WordPress administrator account, and FTP or SSH access if the admin panel has been taken over. I also need login details for the hosting control panel, because the access and error logs matter most in this work, and access to the database. If the domain already has a warning, add access to Google Search Console. It helps to know who has administrator accounts and when the first symptoms appeared.

Can you look after the website after the clean-up?

Yes, and most jobs end that way. After the clean-up, WordPress maintenance can start, from €100 net per month, with weekly updates, backups kept away from the server and monitoring of uptime, the SSL certificate, security and spam blacklists. With a WordPress maintenance plan, any further malware removal is free. For shops, the same applies with OneNet Admin Shop Plus and OneNet Admin Shop Max, from the 2nd full month.

Do you remove malware for UK businesses?

Yes. I work remotely with companies in the UK and the EU, among them a chain of tattoo and piercing studios in the UK and education organisations in Belgium. You deal with me directly, in English. The whole clean-up runs through remote access to the admin panel, the hosting and the database. You can reach me by email, WhatsApp, phone and video call, Monday to Friday, 9:00–⁠17:00 Central European Time (8:00–⁠16:00 UK time).

Do you suspect an infection?

Send me the address of the website and describe the symptom. I reply within 24 hours, and if the infection is confirmed, I start on the same day.

I reply within 24 hours

Free quote

Tell me what needs to be built or fixed. I answer every enquiry myself and do the work myself.