Remove malware, restore access and recover a compromised WordPress website.
● WEBSITE REDIRECTING
Website redirecting to spam or strange pages?
A redirect is not always a mistake, and it is not always visible to the owner. Some malicious redirects only trigger for certain visitors, devices or search results. Dr Web can investigate why the site is redirecting, whether it is a compromise or a fault, and what needs to happen next.
- Investigation of redirect behaviour
- Compromise or configuration fault
- Specialist WordPress recovery
- No passwords needed to start
Why you may not see the redirect yourself
Visitors often report a redirect that the owner cannot reproduce. That does not mean the report is wrong. Malicious code can be written to redirect only certain visitors, such as people arriving from a search result, people on a mobile device or people who are not logged in.
Testing repeatedly can also waste time or put you at risk if the destination is unsafe. It is better to collect what has been reported and get the site investigated than to keep clicking.
● WHAT IT CAN INVOLVE
What a redirecting website can involve
01
Redirects for some visitors only
The site may behave normally for you and redirect people who arrive from Google, use a phone or are visiting for the first time.
02
Code added to the site
Malicious code can be added to theme files, plugin files or content stored in the database. Removing what you can see may not remove the way it returns.
03
Unauthorised access
A redirect can be a symptom of an unknown user, a compromised account or an out-of-date component that gave someone else a way in.
04
Spam pages and search results
A site that redirects visitors may also contain pages that you did not create, and Google may show unexpected text for the domain.
05
Redirects that are settings, not attacks
Redirect loops or unexpected destinations can follow a change to the domain, a security certificate or a redirect plugin. These are faults that need repairing, not malware removal.
06
Redirects that come back
If the redirect disappears and returns, something is probably still in place. The cause needs finding rather than the symptom hiding.
What to do while you wait
01
Record what has been reported
Note the web address people were on, the device they used, how they arrived and where they ended up. Screenshots help.
02
Do not keep testing the redirect
Repeated clicks on an unsafe destination can put you at risk. Do not enter any details on a page that you were redirected to.
03
Keep passwords out of email and forms
Do not send passwords or login details through the public form or ordinary email. A secure method is arranged when access is needed.
04
Avoid deleting files or restoring blindly
Random changes can destroy evidence and can leave the underlying access route open.
Is this a hack or a configuration fault?
It is more likely to be a compromise if:
- only some visitors, devices or search arrivals are redirected
- the destination is spam, gambling, adult or scam content
- pages, files or users appear that nobody created
- the redirect returns after being removed
If the redirect began straight after a change to the domain, SSL certificate, permalink or redirect plugin, or the browser reports too many redirects, Emergency WordPress Repair may be the better path. If you are unsure, submit the symptoms and Dr Web can help work out which it is.
Why Dr Web
01
Specialists in WordPress recovery
Redirect investigations often involve files, database content, users and plugins together. Dr Web treats them as one investigation.
02
Compromise or fault, decided by evidence
Not every redirect is an attack. The first job is to establish which it is, so the right service is used.
03
Not sure what the site runs on?
If you do not know the platform, Dr Web can check what the website runs on and whether it is WordPress before recommending a next step.
04
Written findings
You receive a record of what was found and changed, not just a statement that the redirect has stopped.
How Dr Web investigates a redirect
Tell us what has been reported
Send the website address, who reported the redirect and where they were sent. Do not include passwords.
We check fit and safety
Dr Web reviews the request and recommends the safest first step, including whether the site should stay live while it is investigated.
Investigation is scoped
The scope, access method and quote are agreed before the technical work begins.
Fix, verify and report
The cause is addressed within the agreed scope, the relevant pages are checked and the findings are recorded.
● RELATED RECOVERY FILE
Related Recovery File
This historical case involved injected spam content rather than a visitor redirect. Symptoms and scope vary by website.
Recurring Malware After Host Quarantine
Injected code and casino content were removed, WordPress components were updated, PHP was upgraded from 7.4 to 8.2, and a firewall and malware scanner were configured. The recurring infections stopped.
- FINDINGS
- Quarantining individual files had not addressed outdated application software.
- ACTION
- Injected code and casino content were removed.
Spam Redirect on a Corporate Website
A corporate website began sending visitors to a spam site. A restore from before the compromise was advised, the injected code was removed, and administrator credentials were reset. The client confirmed the redirect had stopped.
- FINDINGS
- Injected code had been inserted into the site.
- ACTION
- A restore of a backup from before the compromise was advised, followed by a malware scan, cleanup and software updates.
Need help with something else?
Frequently asked questions
Malicious code can redirect only certain visitors, such as those arriving from search results or using mobile devices. That is one reason a redirect can be hard for the owner to reproduce.
No. Changes to the domain, SSL certificate, permalinks or a redirect plugin can also cause unwanted redirects. The cause has to be established from the evidence.
Reinstalling WordPress alone does not remove code stored in the database, extra files or an unauthorised user. If the access route is still there, the redirect can return.
Fixing the site is an important step, but Google processes changes in its own time. Dr Web can help with the site-side work and explain what remains outside its control.
It can be sensible to, particularly if the host has issued a notice or suspended the account. The provider controls any suspension and must approve its removal.
Not to start. Dr Web reviews the request first. If access is needed, it is arranged through a secure process, never through the public form or ordinary email.
Get the redirect investigated
Tell us what has been reported and what the website does for the business. Dr Web will review the request and explain the safest next step.