Security · Incident response

Hacked website: malware removal and recovery

If your site redirects to strange places, Google flags it as dangerous or your host has suspended your account, deleting a couple of files is not enough. It needs containing, cleaning thoroughly, closing the door they came in through and checking nothing is left.

Signs you have been hacked

Some are obvious; others go unnoticed for months.

  • Redirects to casinos, pharmacies or spam sites, sometimes only on mobile or when arriving from Google.
  • “This site may be harmful” warnings in Google or in the browser.
  • Pages in Google you did not create: spam in other languages, fake products…
  • Your server sends spam or its IP appears on blocklists.
  • CPU at 100% for no reason: it may be a cryptocurrency miner.
  • Admin users you do not recognise or PHP files where there should only be images.

What I do

It is not just WordPress: PrestaShop, Joomla, Laravel, custom PHP or the Linux server itself.

Website cleanup

Files compared against the official versions, webshells and backdoors removed, including those hidden in images or in the core.

Database and users

Injected content, fake admin users and malicious scheduled tasks.

Compromised server

Cryptocurrency miners, rootkits, persistence processes and services, unknown SSH keys and access that should not exist.

Email and reputation

If the server has sent spam: stop the sending, clean the queue and get off the blocklists.

How I handle an intrusion

Order matters: cleaning without understanding what happened usually ends in a second infection.

  1. 1

    Containment

    A copy of the current state as evidence, cutting off access and stopping active damage.

  2. 2

    Analysis

    How they got in: a vulnerable plugin, a leaked password, another site on the same server…

  3. 3

    Cleanup and lockdown

    Malware out, everything updated, permissions fixed, new passwords and a firewall.

  4. 4

    Report

    What happened, what was done and what is pending, in writing and in plain language.

Technologies

  • WordPress
  • PrestaShop
  • Joomla
  • Laravel
  • PHP
  • Linux
  • Webshells
  • Rootkits
  • Cryptojacking
  • Google Search Console

Frequently asked questions

How long does it take to clean a hacked website?

It depends on the size and how long the attacker has been inside. Containment comes first; I estimate the rest once I see the case.

Is data lost in the cleanup?

The aim is to lose nothing: a full copy is taken before touching anything, and everything removed is kept in quarantine in case it needs to be recovered.

Will they get back in?

If only the malware is deleted, very likely. That is why the way in is found and closed, everything is updated and measures are left in place to detect changes.

Google flags my site as dangerous, what do I do?

After the cleanup, a review is requested in Google Search Console. Once Google confirms the site is clean, it removes the warning.

Do I have to notify anyone?

If customers’ personal data may have been exposed, under the GDPR you may have to notify your data protection authority (in Spain, the AEPD) within 72 hours. In the report I set out what data was exposed so you can assess it.

Contact

Let's talk

Got an idea to build, a platform that has fallen short or a network that keeps scaring you? Tell me. I will tell you how I would do it, how long it would take and what it would cost, with no commitment.

Or email me directly: