lamapixel
0%

WordPress malware removal and hacked site cleanup

Your site is hacked. We clean it up.

Japanese keyword hack, pharma and casino spam, hidden redirects, defaced pages. We remove the infection, find the hole it came through and close it, then get your listing in Google back to normal. You get a written report of what was found and what was changed.

Get my site checked →
lamapixel.com/en/hosting
WordPress malware removal - cleaning an infected site
24-48hTypical cleanup
30Days monitoring after

Most hacked WordPress sites we see fall into three groups.

The symptoms differ, the entry point is usually the same: an outdated plugin, a weak admin password, or a neighbouring site on shared hosting.

SEO spam

Japanese keyword hack

Google shows hundreds of Japanese-language pages under your domain, selling counterfeit goods. Your own pages disappear from the results.

  • Injected pages in the sitemap
  • A rogue user in Search Console
  • Cloaking - the spam is served only to Googlebot
Cloaking

Pharma and casino spam

Your pages look untouched in the browser, but in the search results the titles and descriptions advertise pills, loans or casinos.

  • Modified meta descriptions
  • Hidden links in the footer
  • Conditional output by user agent
Redirects

Malicious redirects and defacement

Visitors land on someone else's site, or the mobile version redirects while the desktop one looks fine. In the worst case the homepage is replaced outright.

  • Injected JavaScript
  • Rules added to .htaccess
  • Backdoors in the uploads folder

Deleting the infected files is the easy part. Keeping them out is the job.

01

We find the entry point

A cleanup that only removes files buys you a few days. We trace how the attacker got in - the vulnerable plugin, the leaked password, the writable directory - and close that specific hole.

02

We repair the Google side

Removing malware does not remove you from the spam index. We clean the sitemap, revoke the attacker's Search Console access, remove the injected URLs and file for reconsideration where a manual action was issued.

30

Days of monitoring after handover

You also get a written report: what was infected, which files changed, which entry point was used, what we hardened. Plain language, so you can hand it to your hosting provider or your client.

From infected to clean, step by step.

01

Scan and backup

We take a full copy of files and database before touching anything, then map the infection: what is modified, what is injected, when it started.

02

Removal

Core, plugin and theme files are compared against clean originals. Injected code is stripped, backdoors and rogue admin accounts are removed.

03

Closing the door

Updates, file permissions, disabled PHP execution in uploads, two-factor on the admin, and a login URL that is not /wp-admin.

04

Recovery in Google

Clean sitemap, removal of spam URLs, revoked attacker access in Search Console, reconsideration request, then monitoring until impressions recover.

Questions about hacked site cleanup

Not sure whether your site is infected? Send us the URL - the initial check costs nothing.

Live · Online
We reply within 24 hours · Initial check free
Open contact form
7 000 KcCleanup from
24-48hTypical turnaround
DIAGNOSISHow do I know my WordPress site has been hacked?
The clearest test is a Google search for site:yourdomain.com. If you see pages you never created - Japanese characters, pharmacy or casino titles, random strings - the site is serving injected content. Other signals: Search Console reports "This site may be hacked", the site redirects on mobile but not desktop, admin users appear that you did not create, or your hosting provider warns about outgoing spam. Note that many infections are invisible in a normal browser, because the spam is served only to Googlebot.
JAPANESE HACKWhat is the Japanese keyword hack and why did it target my site?
It is an automated SEO spam attack. The attacker injects thousands of Japanese-language pages selling counterfeit goods, adds them to your sitemap, and registers themselves in your Search Console to speed up indexing. It is not personal - bots scan the whole internet for a known vulnerability, usually an outdated plugin, and take whatever they find. The value they extract is your domain's reputation in Google.
GOOGLEHow do I remove the "This site may have been hacked" warning from Google?
The warning disappears on its own once Google recrawls the site and finds it clean - but only after the spam is genuinely gone, including the injected URLs already in the index. The sequence that works: remove the infection and the backdoors, clean the sitemap so it lists only real pages, remove the attacker's account from Search Console, request removal of the spam URLs, and then file a reconsideration request if a manual action was issued. Expect days rather than hours.
RANKINGSWill my Google rankings come back after the cleanup?
Usually yes, but not instantly. Once the spam is gone and Google has recrawled the site, impressions typically return over a few weeks. How fast depends on how long the infection was live and whether a manual action was applied. Sites cleaned within days of infection tend to recover fully; sites that were spamming for months take longer and sometimes settle slightly below where they were.
DIYCan I clean a hacked WordPress site myself?
You can, and our step-by-step guide walks through it. It works when the infection is recent and limited to a plugin's files. Where people usually get caught out: backdoors dropped in the uploads folder or in mu-plugins, a scheduled task that reinstalls the malware, a second admin account, and the Google side of the job that most tutorials skip entirely. If the site starts reinfecting itself within days, something was left behind.
PRICEHow much does WordPress malware removal cost?
Cleanup starts at 7 000 CZK for a standard WordPress site. The initial check is free - send us the URL and we tell you what we find, whether or not you hire us. The final number is fixed before we start and depends on the scope: how many sites are affected, whether the hosting account itself is compromised, and whether Google issued a manual action.
TIMELINEHow long does the cleanup take?
We clean most sites within 24 to 48 hours, hardening and the Search Console work included. What takes longer is Google: recrawling and dropping the spam URLs from the index runs over days to a few weeks, and that part is outside anyone's direct control. Monitoring runs for 30 days after the cleanup, so a reinfection surfaces while we are still on it.
PREVENTIONHow do I stop it from happening again?
Most reinfections come back through the same door. Keeping WordPress, plugins and themes updated closes the majority of it. Beyond that: two-factor authentication on every admin account, PHP execution disabled in the uploads directory, a login URL that is not the default, removal of plugins you no longer use, and backups stored somewhere other than the server itself. Our hardening guide covers the full list.

Send us the URL of the affected site. The initial check is free and we tell you what we find within 24 hours - whether or not you hire us for the cleanup.

Get my site checked