Remove WordPress malware
Your site redirects visitors to external pages, Google displays a warning, the backend lists administrators you never created, or you no longer have access yourself. I will remove the malware completely and close the vulnerability through which it reached your server.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
Daran erkennen Sie, dass etwas nicht stimmt
No single point is proof on its own, and not everything has to apply. If any of this sounds familiar, you should have the installation checked. Anyone searching for the complaints in everyday language will find the same service under Remove WordPress virus.
You can no longer access the backend
The password is suddenly no longer accepted, or your account has been downgraded from administrator to subscriber. Whoever has gained access will generally lock the owner out first.
Administrators you never created
Unter Benutzer there are accounts with technically sounding names and addresses that don't exist. In the current cases, for example wpsvc_…@wordpress-svc.internal.
Fremde Plugins oder Themes
Namen wie „Database Repair Assistant“ oder „wp2s-606aa615“ klingen nach Technik und sind Hintertüren. Manche blenden sich zusätzlich aus der Plugin-Liste aus, damit Sie sie gar nicht erst sehen.
Dateien kommen immer wieder zurück
You delete a strange .htaccess or clear the index.php auf – am nächsten Tag ist alles wieder da. Dann läuft im Hintergrund noch etwas, meist ein Cronjob oder eine zweite Hintertür.
Visitors end up elsewhere
Die Seite leitet auf Glücksspiel-, Pillen- oder Fake-Shops um. Oft nur bei Aufrufen aus der Google-Suche und nur auf dem Handy – damit es dem Betreiber möglichst lange nicht auffällt.
Google warnt vor Ihrer Seite
“This website may harm your computer” in the search results, a red warning page in Chrome or a message in the Search Console under Security issues.
Foreign subpages in the Google index
Eine Suche nach site:ihre-domain.de zeigt hunderte Seiten mit japanischen oder kyrillischen Zeichen, die es auf Ihrer Website gar nicht gibt.
Your emails are no longer getting through
Der Server verschickt im Hintergrund Spam, die Domain landet auf Blacklists – und plötzlich erreichen Ihre Angebote und Rechnungen niemanden mehr.
Der Hoster hat abgeschaltet
IONOS, Strato, All-Inkl und andere sperren betroffene Pakete, sobald Beschwerden auflaufen. Für die Freischaltung muss die Bereinigung nachvollziehbar dokumentiert sein.
The most unpleasant case is one with no symptoms at all. An infection remains unnoticed for months and is only used when it becomes worthwhile, or it is quietly rented out to third parties. A scan is therefore worthwhile even when the site is running normally.
Why so many sites are currently infected
WordPress had a serious security vulnerability in July 2026. Attackers could use it to take over a website without knowing the password and without an insecure plugin having to be installed. WordPress has since closed the vulnerability with an update.
The update only eliminates the vulnerability itself, however. If a website was attacked beforehand, a hidden backdoor remains, such as an additional administrator, a manipulated file or an inconspicuous plugin. A fully updated WordPress site can therefore still be compromised today. Anyone who used an affected version in the weeks before the security update should also have the installation checked to determine whether files, user accounts or settings were changed.
So läuft eine Bereinigung ab
You get in touch
You can reach me by phone or via the form. I will get back to you within 4 hours and ask what happened, since when it has been noticeable and which access details you have available. After that, it will be clear whether an inspection is sufficient or whether the site will be cleaned up immediately.
Sie geben mir die Zugänge
I need SFTP or SSH access, database access and an administrator account. An infected site cannot be repaired from the browser; the reasons for this are explained further below. I treat all company and customer data with strict confidentiality.
Backup before I intervene
First, I make a complete copy of the files and database in the infected state. This means that cleaning up does not damage your existing customer data.
Scan und Befund
Your website will be thoroughly scanned for malicious code, and every anomaly will be investigated immediately.
Cleanup
The core, plugins and themes are replaced with clean originals. Malicious code is removed individually from everything that cannot be replaced, namely your content, your theme and your uploads. Foreign user accounts, scheduled tasks and disguised files are deleted. Afterwards, all passwords and security keys are changed.
Angriffsvektor schließen und übergeben
The route through which access was obtained is closed. If requested, I will handle the removal of the warning with Google and the host. If your insurance covers the costs and requests a damage report, you will receive one for an additional fee.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
My three promises
€280 fixed price
€280 net for the cleanup, no surprises on the invoice.
6 hours – or half price
From the moment I have all the access details, your site will be clean and accessible again within 6 hours. If it takes longer, you only pay half. Applies Monday to Friday from 8 a.m. to 8 p.m.
Money-back guarantee
If I can't clean the site or restore its original state, you will receive a full refund. No discussion and no partial invoice for the attempt.
What I need from you
An infected site cannot be repaired from the outside. What a scanner sees through the browser is merely the surface. The actual malicious code is located in files, database tables and server configurations, which can only be accessed with genuine access credentials. I therefore assume that you can provide me with the following:
- SFTP or SSH access to the web space – SSH is considerably faster
- Access to the MySQL database – phpMyAdmin is sufficient, direct access is better
- An administrator account in WordPress
- Access to the hoster's customer panel, if anything needs to be changed in DNS or server configuration
If you do not have this data to hand, you can obtain it from your hoster as the contract holder. I will tell you on the phone what to ask for and where to find it in the respective customer menu.
At the end, all passwords are reset anyway, so my login details are also worthless afterward. This step is part of the cleanup and is non-negotiable, because old login details are the most common reason an infection recurs.
Die Seite läuft gar nicht mehr?
A white page, a 500 error, a database error or a blocking message from the host are not exclusion criteria. Via SSH or SFTP, I can also access an installation that no longer delivers anything in the browser.
Only one point is important: Do not rebuild the site now and do not restore a backup before we have spoken. Otherwise, the traces will be lost, and without traces it is impossible to determine how access was obtained. In this case, experience shows that the same attack will occur again within a few weeks.
Frequently asked questions
Can't I remove the malware myself?
If you are familiar with SSH, file checksums and SQL, it is certainly possible. The time involved is usually the point at which it becomes impractical. The actual work consists of being certain that the suspicious file was the only one. To do this, every file must be compared with the original, the database must be searched and the entry point must be found in the logs. Anyone doing this for the first time generally needs two days and often overlooks the second backdoor in the process.
Isn't a security plugin like Wordfence or Sucuri enough?
Such plugins are useful for prevention, and I use them myself. They are only of limited use for removing an infection. They detect known patterns, while obfuscated, individually written or code stored in the database often remains undetected. There is also a fundamental problem: A plugin runs inside the installation it is supposed to check. Anyone with administrator rights can disable it or make it believe it is seeing a clean installation. That is why I check from the outside, via SSH and directly in the database.
Isn't it easier to set up the entire site from scratch?
In some cases, that is true, and I will tell you so. However, two points often speak against it. First, your content, images, forms, orders and Google rankings depend on it, so rebuilding generally costs significantly more than 280 €. Second, it does not solve the problem: If the entry point was a leaked FTP password or an outdated plugin, the new site is just as exposed as the old one. Without knowing the cause, the problem simply reappears.
How long does it take?
The scan alone usually takes half a day because checking and reviewing the logs takes time. A standard cleanup is completed within 6 hours, calculated from the moment I have received all access credentials; the commitment stated above still applies. Very large installations, shops with ongoing orders and cases in which the host needs to cooperate require more time. I will inform you about this before starting the work.
Meine Seite ist bei Google als schädlich markiert. Geht das wieder weg?
Ja. Nach der Bereinigung wird in der Google Search Console eine Überprüfung beantragt; Google schaut sich die Seite dann erneut an und nimmt die Warnung heraus. Das dauert üblicherweise ein bis drei Tage. Wichtig ist, dass die Seite zu diesem Zeitpunkt wirklich sauber ist – wird beim zweiten Anlauf noch etwas gefunden, verlängert sich die Wartezeit spürbar. Denselben Weg gehe ich bei Bedarf mit dem Hoster, der eine Sperre gesetzt hat.
What if I don't have a backup at all?
Das ist der Normalfall. Ein Backup macht die Sache bequemer, ist aber keine Voraussetzung, und häufig ist es ohnehin nutzlos, weil der Befall älter ist als die Sicherung und man sich das Problem damit zurückspielt. Bereinigt wird der vorhandene Bestand: Kern, Plugins und Themes kommen als saubere Originale zurück, Ihre eigenen Inhalte werden Schritt für Schritt von Schadcode befreit.
Muss ich den Vorfall melden?
Das ist möglich. Wenn personenbezogene Daten betroffen sein könnten, also Kontaktformulare, Kundenkonten, Bestellungen oder Newsletter-Adressen, sieht Artikel 33 DSGVO eine Meldung an die zuständige Landesdatenschutzbehörde innerhalb von 72 Stunden vor. Aus dem Befund geht hervor, worauf zugegriffen werden konnte und in welchem Zeitraum; diese Angaben benötigen Sie für die Meldung. Die Meldung selbst müssen Sie vornehmen, und ob sie erforderlich ist, bleibt eine Rechtsfrage, die ich Ihnen nicht abnehmen kann.
Will the hack come back?
Über denselben Weg tritt der Befall nicht erneut auf, weil dieser Weg geschlossen wird; das ist Teil des Auftrags. Neue Lücken entstehen allerdings laufend, in WordPress selbst und in jedem Plugin, das Sie einsetzen. Die wp2shell-Lücke vom Juli 2026 hat vollständig gepflegte Seiten getroffen, die lediglich wenige Tage zu spät aktualisiert wurden. Wer das nicht selbst verfolgen möchte, ist mit der laufenden Betreuung ab 65 € im Monat besser aufgehoben; dort ist die Bereinigung im Ernstfall enthalten.
Do you also work outside Schleswig?
Ja. Der größte Teil der Arbeit läuft ohnehin per Fernzugriff, sodass der Serverstandort keine Rolle spielt und für Sie kein Unterschied entsteht. Ich arbeite bundesweit für Kunden von Flensburg bis München. Wenn Sie aus Schleswig, Flensburg, Rendsburg oder der Umgebung kommen und lieber persönlich sprechen möchten, ist das ebenfalls möglich.
And what if the scan finds nothing at all?
Dann erhalten Sie das Ergebnis schriftlich, zusammen mit dem Prüfumfang und einer Liste der Punkte, die mir sonst aufgefallen sind, etwa veraltete Plugins, schwache Passwörter oder offene Konfigurationen. Das kostet die 50 € und ist gut angelegt: Sie wissen danach, dass die Ursache an anderer Stelle liegt, und können gezielt weitersuchen.
The longer an infected site remains online, the more expensive it becomes
Der Schaden wächst unabhängig von den Kosten der Bereinigung weiter. Eine Google-Warnung lässt sich nur langsam wieder ausräumen, eine Domain auf einer Spam-Blacklist benötigt Wochen bis zur Entfernung, und jeder weitere Tag gehört denjenigen, die sich in Ruhe einen zweiten und dritten Zugang anlegen. Ein Anruf kostet Sie nichts und dauert fünf Minuten.
Erreichbar montags bis freitags von 8 bis 20 Uhr · Wochenendeinsätze auf Anfrage gegen 100 € Pauschale
In Alltagssprache: WordPress-Virus entfernen · Verwandte Fälle: Schadcode entfernen, fremde Seiten im Index, WordPress absichern · Übersicht: alle Themen und Regionen
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.