Snapshot and evidence
Before touching anything, we copy the files, database and web server logs. That copy is what we use to find the entry point, and it matters if legal follow-up is needed.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
Your site redirects to gambling pages, Google shows a warning under your listing, or your host suspended the account for sending spam. In a hacked website cleanup, we first copy the current files and logs so the evidence of the break-in survives, then remove the malicious code and trace how the attacker got in. Deleting infected files without closing that entry point usually leads to reinfection.
Hacked website cleanup is the removal of malicious code and backdoors from a compromised site or server, together with closing the entry point the attacker used so the infection does not return. It is needed when a site redirects visitors elsewhere, Google shows a hacked-site warning under your listing, or your host suspends the account for sending spam. PikoSystem first copies files, the database and web server logs to preserve evidence, finds malicious code with Maldet, ClamAV and pattern searches, replaces WordPress core and plugin files with clean official copies, reviews web server, SSH and FTP logs to trace the break-in, and rotates passwords and wp-config.php keys. After cleanup, a review request is filed in Google Search Console. You receive a cleaned site, a report on the entry point and the new credentials.
Before touching anything, we copy the files, database and web server logs. That copy is what we use to find the entry point, and it matters if legal follow-up is needed.
We find malicious code with Maldet, ClamAV and searches for patterns like eval(base64_decode, PHP files inside the uploads folder and recently modified files. We also check the wp_options and wp_posts tables for injected scripts.
We replace WordPress core and plugin files with clean official copies and remove backdoors, unknown admin users and suspicious cron jobs.
We go through web server access logs and SSH and FTP logs to pin down a vulnerable plugin, a leaked password or another infected site on the same server.
We rotate passwords and the security keys in wp-config.php, update or remove vulnerable plugins and fix file permissions.
After the cleanup, we file a review request in Google Search Console. How long the review takes is up to Google.
Much malicious code runs only for a specific audience. A redirect may fire only for visitors arriving from Google on a phone, while an admin logged into WordPress sees nothing unusual. That is why site owners are often the last to find out.
For a quick check, search Google for site: followed by your domain. Pages with Japanese, gambling or pharmacy titles that you never created point to an SEO spam hack. Look at Security Issues and the users list in Search Console too, since attackers sometimes add themselves as owners.
Security plugins such as Wordfence run inside the same WordPress install that was compromised. Malware can hide from them or simply disable them, and they cannot see files outside the site folder, other sites on the same hosting account or server cron jobs.
A manual cleanup checks file integrity with wp core verify-checksums and wp plugin verify-checksums in WP-CLI and compares files against official copies. Nulled themes and plugins downloaded from unofficial sites are a common source of infection and should be replaced with genuine versions or removed.
If the attacker only had the web server user's access, cleaning the site files and closing the entry point is usually enough. Once there are signs of root access, the operating system itself can no longer be trusted. Examples include unknown keys in root's authorized_keys, an /etc/ld.so.preload file, unfamiliar kernel modules, modified binaries such as ps or ls, and a cryptominer process eating CPU.
The safe path then is a fresh OS install, moving data across after it has been checked, and rebuilding the configuration. Trying to clean a server with a rootkit in place can leave a backdoor that even rkhunter misses.
Block PHP execution in wp-content/uploads with an .htaccess or Nginx rule, since that folder is a favorite spot for backdoors. Set DISALLOW_FILE_EDIT in wp-config.php to turn off the built-in file editor, and enable two-factor login for admin accounts.
Keep each site in its own hosting account or system user so one infection cannot spread to the rest. Delete inactive plugins and themes, because their vulnerable files can still be exploited while deactivated. Run updates on a fixed schedule, with a backup taken first.
You describe what is happening. If needed, we put the site into maintenance mode so visitors are not exposed.
We copy the current state, map how far the infection has spread and tell you what is affected.
We remove the malicious code, close the entry point and change the passwords.
After the cleanup, we keep an eye on the site for signs of reinfection and deliver the final report. The length of this watch period is set in the agreement.
Nobody can honestly promise that. We find and close the hole used this time and reduce the other openings. Keeping plugins and hosting updated after handover has a big effect on what happens next.
Yes, we also work on shared hosting with cPanel or DirectAdmin. We see less of the server logs and settings there, so tracing the entry point may need help from your host's support team.
If you have a clean backup from before the break-in, restoring is one option. Without closing the entry point, though, the restored site gets infected again. It is also often unclear when the infection started, so the backups themselves need checking.
Logs and the database can show what the attacker had access to. If we see signs of data theft, we tell you, and a deeper investigation is handled under our digital forensics service.
Related searches
Urgent
For a full outage, a phone call is the fastest route. If you can't call, fill in the form and we'll call you.
Call now 0900-000-0000