Skip to content
My Site Got Hacked Get help now

Malware removal

WordPress malware removal

Your site is infected. We remove it properly — including the backdoor that a plugin scan will not find — and tell you exactly how it happened.

Start here if you are seeing any of this

You do not need to work out what kind of infection it is. Describing the symptom is enough for us to know where to look.

Google says the site may harm your computer

Chrome and Safari are showing an interstitial warning to anyone who tries to visit. The site is on a Google blacklist, and every hour it stays there costs you traffic.

Google Ads suspended your account

The dreaded "malicious or unwanted software" email. Ads stay suspended until the site is clean and the review passes. We handle the clean and the appeal.

Japanese keywords in your search results

Your listings have been replaced with pages you never wrote, usually in a language you do not speak. The infection is generating spam pages and Google has indexed them.

The site redirects somewhere else

Visitors land on gambling, pharmacy or scam pages. Often it only fires for mobile visitors or first-time visitors, which is why it can run for weeks before anyone tells you.

Admin accounts you do not recognise

Extra users with administrator rights, or your own login no longer working. The attacker has a persistent way back in that a plugin scan will not remove.

The host suspended your account

Your site has been taken offline for sending spam or consuming resources. Hosts rarely restore access until you can show the infection is gone.

What the clean-up covers

The difference between a site that stays clean and one that is reinfected next week is almost always the backdoor nobody looked for.

Manual removal, not a plugin scan

Scanners find the payload. They routinely miss the backdoor — a small, legitimate-looking file that lets the attacker straight back in. We go through the file tree and the database by hand.

Core, theme and plugin integrity check

Every WordPress core file is compared against the official release. Themes and plugins are checked for injected code, and anything abandoned by its developer is flagged.

Database clean-up

Injected scripts in post content, malicious options and cron entries, and spam pages generated by the infection all get removed.

User and access audit

Unknown administrator accounts, rogue API keys, unauthorised SSH keys and FTP users are removed, and legitimate credentials are rotated.

Google and host warnings lifted

Where the site is flagged in Search Console or blocked by your host, we lodge the review and follow it through until the warning clears.

A written explanation

What was found, what was removed, how they got in, and what to change. In plain English, not a scanner log.

How it runs

  1. 01

    Tell us what you are seeing

    Send the symptom and the URL. You do not need to diagnose it — describing what changed is enough.

  2. 02

    We assess and quote

    We look at the site from the outside, and inside if you have given us access. You get a fixed price and a timeline before anything is touched.

  3. 03

    Backup, then clean

    A full copy of the site and database is taken first. Then the infection is removed by hand — not by a plugin scan that misses the backdoor.

  4. 04

    Close the entry point

    Whatever let them in gets fixed: an abandoned plugin, a weak password, an out-of-date core, a compromised host account.

  5. 05

    Clear the warnings

    Where the site has been flagged by Google or your host, we lodge the review and follow it through until the warning is lifted.

  6. 06

    You get the write-up

    A plain-English summary of what was found, what was removed, how it got in, and what to do next.

Pricing

Fixed price, agreed before we start. Full detail on the pricing page.

Emergency Clean

Your site is infected and you need it clean.

$499

one-off, per site · ex GST

Blogs and brochure sites

  • Full malware scan and manual removal
  • WordPress core, theme and plugin integrity check
  • Backdoors and unknown admin accounts removed
  • Google Search Console review request where the site is flagged
Get started
Most chosen

Clean & Harden

Clean it, then close the door that let them in.

$899

one-off, per site · ex GST

Business sites that cannot afford a repeat

  • Everything in Emergency Clean
  • Core, theme and plugin updates applied and tested
  • Abandoned and vulnerable plugins identified and replaced
  • Server-side and WordPress hardening applied
Get started

Recover & Protect

A serious compromise, or a site you cannot risk losing again.

$1,499

one-off, then from $149/month · ex GST

E-commerce, membership and lead-critical sites

  • Everything in Clean & Harden
  • Rebuild from clean source where the infection is too deep to excise
  • Blacklist and ad-account reinstatement handled end to end
  • Ongoing monitoring with alerting
Get started

Think your site is infected?

Send us the URL and what you are seeing. We will tell you what we find, what it will cost, and how long it will take — before anything is touched.