Remove malware, restore access and recover a compromised WordPress website.
● WEBSITE HACKED
My website has been hacked. What should I do first?
A hacked website can look normal to you while visitors, Google or your host see something different. Start by recognising the signs and avoiding changes that make recovery harder. Dr Web can check the website, identify the platform if you are not sure what it runs on, and explain the safest next step.
- Plain-English first steps
- Works if you do not know the platform
- Specialist WordPress recovery
- No passwords needed to start
The signs of a hacked website are not always obvious
Some hacks are loud. The site is defaced, visitors are redirected or a browser shows a warning. Others are quiet. The site looks fine when you visit it, but customers report strange pages, Google shows text that you did not write, or an administrator account appears that nobody created.
A single sign is not proof, and a clean-looking homepage is not proof that the site is healthy. What matters is the pattern: unexpected changes, unexpected access or unexpected behaviour that the business did not authorise.
● WHAT IT CAN INVOLVE
What a hacked website can involve
01
Redirects and unwanted pages
Visitors may be sent to another website, or the site may contain pages that you did not create. Some redirects only appear for certain visitors, so you may never see them yourself.
02
Spam in search results
Google may show unexpected titles or descriptions for your domain, often about unrelated products or services. The site can look normal when you visit it directly.
03
Unknown users or changed access
An administrator account that nobody created, or a legitimate account that changed without explanation, can indicate that someone else has access.
04
Files or plugins you do not recognise
Unfamiliar files, disabled security tools or plugins that you did not install can be part of a compromise. They can also have innocent explanations, which is why the evidence needs checking.
05
Warnings from a browser, host or security tool
A security notice from your hosting provider, a browser warning or a malware report is a strong reason to have the site checked. It does not tell you the cause or the full extent of the problem.
06
Loss of access
You may be locked out of the WordPress dashboard, or the website may have stopped loading. Loss of access can be a compromise, a fault or both.
What to do in the first hour
01
Note what you can see
Write down what you have noticed, where and when. Screenshots and the web addresses involved are useful. This helps the assessment and avoids guesswork.
02
Avoid random changes
Deleting files, reinstalling plugins or restoring old backups without understanding the cause can destroy evidence and leave the access route in place.
03
Keep passwords out of email and forms
Do not send passwords or login details through the public form or ordinary email. Dr Web will explain a secure access method when access is needed.
04
Speak to your host and get a specialist to check
Your hosting provider may need to know, particularly if a suspension notice has been issued. A specialist can check the site and advise on containment before further changes are made.
Is this a hack or a fault?
It is more likely to be a compromise if you see:
- redirects or pages that you did not create
- spam or unfamiliar text in Google results
- administrator accounts that nobody recognises
- a warning from a browser, host or security tool
- security plugins switched off without explanation
If the site is simply broken, showing an error message or offline with no signs of compromise, Emergency WordPress Repair may be the better path. If you are unsure, submit what you can see and Dr Web can help work out which it is.
Why Dr Web
01
A specialist first look
Dr Web focuses on WordPress recovery and care. You deal with people who see compromised websites as a specialist problem, not a general web task.
02
Investigation beyond a scan result
A clean scan does not always explain an intermittent redirect or a hidden way back in. The files, database, users and output can all need review.
03
Not sure what the site runs on?
If you do not know the platform, Dr Web can check. WordPress is the specialty, and the first step is to identify what the website is and what has happened.
04
Written findings
Important findings and actions are recorded, so you are not left with a vague statement that the site is clean.
How Dr Web handles a hacked website
Tell us what you can see
Send the website address, what you have noticed and what the site does for the business. Do not include passwords.
We check fit and safety
Dr Web reviews the request, establishes the platform where needed and recommends the safest first action.
Recovery is scoped
If the site needs recovery, the scope, access method and quote are agreed before the work begins.
Verify and report
Agreed checks are completed and the findings are recorded, including anything that remains with a third party.
● RELATED RECOVERY FILE
Related Recovery File
Website Outage & Compromise
A verified earlier backup was restored, malicious files and unauthorised administrator access were removed, and the public website and administration area were confirmed operational.
- FINDINGS
- The website had been compromised.
- ACTION
- A verified earlier backup was restored.
Server Restored to a Pre-Attack State
After a compromise, the whole hosting server was restored to its state from before the attack. Mailbox passwords were reset, and because nothing was maintaining the server, a maintenance plan covering updates, cleanup and malware scans was recommended.
- FINDINGS
- The compromise affected the whole hosting server, not just one site.
- ACTION
- The entire server was restored to a point before the compromise.
Need help with something else?
Frequently asked questions
Common signs are redirects, spam in search results, unknown administrator accounts, unfamiliar files and warnings from a browser, host or security tool. No single sign proves it, so the site needs checking.
It depends on what is happening and what the site does for the business. Avoid random changes, and get advice before removing pages or restoring backups. If visitors are being harmed, restricting public access where practical can be sensible.
A backup can be part of a recovery, but restoring it without finding how the site was compromised can bring the problem straight back. The backup also needs to be checked.
No. Dr Web specialises in WordPress and can check what the website runs on before recommending a next step.
Not to start. Dr Web reviews the request first. If access is needed, it is arranged through a secure process, never through the public form or ordinary email.
Dr Web can investigate and remove the malicious changes that it identifies within the agreed scope. It cannot promise that every unknown issue can be found before an assessment, or control how quickly third parties react.
Get the website checked
Tell us what you have noticed and what the website does for the business. Dr Web will review the request and explain the safest next step.