Remove WordPress Virus
Your website redirects visitors to external pages, displays unknown advertisements, or you can no longer access the backend yourself. Colloquially, this is called a virus; technically, there is malicious code on your server. I remove it completely and close the vulnerability through which it got there.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
Does one of these sentences sound familiar?
People affected call me using these sentences. None of them is proof on its own, and not everything has to apply. If you recognise yourself in one of them, you should have the installation checked. If you are familiar with the term “Malware” and are specifically searching for it, I describe the same service under Remove WordPress malware from a technical perspective.
„I can no longer log in to WordPress“
Your password is no longer accepted, even though it is correct. In other cases, you can still log in but see only part of the interface because your account has been downgraded from administrator to subscriber. Whoever gains access usually locks the owner out first.
„There are users here I never created“
Under Users, accounts with technical-sounding names and email addresses that do not exist suddenly appear. Please do not delete these accounts immediately. As long as they are present, it is possible to determine when and by which route access occurred.
„Suddenly there are plugins installed that I do not recognise“
The plugin list contains entries that sound like system tools and appear inconspicuous. That is precisely what the naming is intended to achieve, because they are backdoors. Some also hide themselves from the plugin overview, so you cannot see them in the backend at all.
“I delete it, and it's back the next day”
You remove a suspicious file, and the next morning it is back. In this case, something is still running in the background, usually an automated task on the server or a second backdoor that keeps restoring the first one. Deleting individual files will not solve the problem.
“My website redirects to an external page”
Anyone who enters your address ends up on pages for gambling, medication or fake shops. This often happens only when accessing the site from Google search results and only on mobile devices. On your own computer, everything looks unchanged, which is why your customers often notice it first.
“The browser is warning about my own website”
Chrome or Firefox displays a red warning page before your website, or the search result shows the notice “This website may harm your computer”. At this point, it becomes expensive, because as long as the warning is displayed, practically no one visits the site.
“There are pages on Google that do not exist on my site”
A search for your own address reveals hundreds of subpages with foreign characters or brand names. Your website is being misused as a vehicle for someone else’s advertising, without any of it being visible in the backend.
“My emails are no longer getting through”
Offers and invoices no longer reach the recipient or end up in the spam folder. The typical cause is that large amounts of advertising are being sent in the background via your server, which is why your domain is on a blocklist.
“My hoster has shut down the website”
IONOS, Strato, All-Inkl and other providers suspend affected hosting packages as soon as complaints accumulate, sometimes without warning. To reactivate them, they require credible proof that the cleanup has been completed.
The most problematic case is one with no symptoms at all. Malicious code can remain unnoticed for months and is only activated when it becomes worthwhile. A scan is therefore advisable even when your site is running completely normally.
Why so many are affected right now
In July 2026, a serious security vulnerability in WordPress itself became known. Attackers could take over a website through it without knowing a password; it was enough for the site to be accessible. Fully maintained installations that received the update a few days too late were also affected.
The vulnerability has since been closed. However, an update only removes the vulnerability itself, not what had already reached the server beforehand. Anyone attacked during this period still has the backdoor on the server. These are currently the cases I deal with most often.
This is how you get rid of the virus
You tell me what is going on
You can reach me by phone or via the form. I ask what you have observed, since when it has been noticeable and which access details you can use. After the conversation, you will know what the situation is and what the processing will cost, and I will know whether an examination is sufficient or whether the site should be cleaned immediately.
You hand over your login details to me
I need SFTP or SSH access, database access and an administrator account. Infected code cannot be found or removed reliably through the browser alone. I will of course treat your company and customer data confidentially.
I back up the current state before intervening
Before I intervene, I make a complete copy of the files and database in their current, infected state. This means nothing can be lost during the cleanup, neither your content nor orders or customer data.
I'm looking for the malicious code
Every file is compared with the clean original, the database is searched and the access logs are evaluated. In the end, it is clear which malicious code is present on the site and by which route and at what time it got there.
I remove the malicious code
The core, plugins and themes are replaced with clean originals. The malicious code is removed individually from everything that cannot be replaced, namely your texts, your images and your customised theme. Foreign user accounts, hidden files and automated tasks are deleted. All passwords and security keys are then renewed.
I close the entry point
Finally, the route through which access was obtained is closed; otherwise the same problem will reappear on the site within a few weeks. If you wish, I can handle the removal of the warning at Google and the unblocking by the hoster. If your insurance requests a damage report, you will receive one for an additional fee.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
My three promises
€280 fixed price
€280 net for the cleanup, no surprises on the invoice.
6 hours – or half price
From the moment I have all the access details, your site will be clean and accessible again within 6 hours. If it takes longer, you only pay half. Applies Monday to Friday from 8 a.m. to 8 p.m.
Money-back guarantee
If I can't clean the site or restore its original state, you will receive a full refund. No discussion and no partial invoice for the attempt.
What I need from you
An infection cannot be fixed from the outside. What a scanning service sees through the browser is merely the surface. The actual malicious code is located in files, database tables and server settings, which can only be accessed with genuine access. That is why I need the following from you:
- SFTP or SSH access to your webspace; processing via SSH is significantly faster
- Access to the database; phpMyAdmin is sufficient; direct access is more convenient
- An administrator account in WordPress; if you are locked out, this can be resolved through the database
- Your hoster's customer menu, if anything needs to be changed in DNS or server settings
If you do not have this data to hand, you can obtain it from your hoster as the contract holder. I will tell you on the phone what to ask for and where to find it in the respective customer menu.
At the end, all passwords are reset anyway, so my login details are also worthless afterward. This step is part of the cleanup and is non-negotiable, because old login details are the most common reason an infection recurs.
The site does not load at all?
A blank page, a 500 error, a database error or a hoster’s blocking page are not an obstacle. Via SSH or SFTP, I can also access an installation that no longer displays anything in the browser.
Only one thing matters: Do not rebuild the site now and do not restore a backup before we have spoken. Otherwise, all traces will be lost, and without traces it is impossible to determine how the access was gained.
Questions I'm asked on the phone
Can a website even have a virus?
In the sense of a classic computer virus that spreads on its own, this is not the case. Infected websites contain malicious code: files someone uploaded, modified system files, database entries and often an additional administrator account as a second means of access. This distinction is practically important because it determines the entire removal process. An antivirus scanner on your computer will not find any of this because the malicious code is on the server.
Can the virus get from my website to my computer?
The target of such an attack is usually your visitors. The malicious code is on the server and is delivered to everyone who visits your site. However, there is one important exception: The initial access often occurs in the opposite direction because login credentials stored on the operator’s computer were stolen. For this reason, I always ask who has access and which devices are being used.
I can no longer get into WordPress. Is it a virus?
That is not necessarily the case. A login can also fail because of a minor issue, such as a faulty plugin, a full database or an incorrectly set password. It becomes suspicious if your password is demonstrably correct, if your account suddenly has fewer permissions or if other irregularities occur at the same time. This can be assessed within a few minutes on the phone, and if the cause is harmless, I will tell you that as well.
My site no longer loads. Is it a virus or a technical error?
Both causes occur, and from the outside they look identical. A white page or a 500 error can result from a failed update just as well as from maliciously injected code. This can only be clarified through the server's error logs. That is exactly where I start, which is why a site that is no longer reachable is not an exclusion criterion for me.
What does it cost to have the malicious code removed?
The scan costs €50 net and provides a definitive answer as to whether malicious code is present on the site and what kind. Complete cleanup costs €280 net at a fixed price, with the €50 credited toward it. There is neither hourly billing nor additional charges. If I cannot clean the site properly, you pay nothing.
Is a security plugin enough?
Such plugins are useful for prevention, but only to a limited extent when it comes to removing an infection. They detect known patterns, while individually written or well-hidden code often remains undetected. There is also a fundamental problem: The plugin runs inside the installation it is supposed to check. Anyone who has gained administrator rights can disable it or make it believe everything is clean. That is why I check from the outside, via server access and directly in the database.
How long does the processing take?
The scan alone usually takes half a day because comparing the files and reviewing the logs takes time. Normal cleanup is completed within 6 hours, starting from the moment I have all the login details; if it takes longer, you pay only half. Very large sites, shops with ongoing orders and cases where the hoster has to cooperate take more time. I will inform you of this before starting the work.
Can I remove the malicious code myself?
With experience in server access and databases, this is certainly possible. The real difficulty is knowing for certain that the suspicious file was the only one. To do this, every file must be compared with the original, the database must be searched and the point of entry must be identified in the logs. Based on experience, anyone doing this for the first time needs two days and often overlooks the second backdoor. If you want to try it yourself, do not delete anything beforehand and first back up the current state.
Will the warning disappear from Google again?
Yes. After the cleanup, a re-review is requested in Google Search Console; Google then checks the site once more and removes the warning. This usually takes one to three days. What matters is that there really is nothing left at that point, because if something is found during the second attempt, the waiting time is extended noticeably. If necessary, I follow the same procedure with a hoster that has imposed a block.
Can the infection happen again?
The infection will not recur through the same route because that route is closed; this is part of the service. However, new vulnerabilities are constantly emerging, both in WordPress itself and in every plugin in use. The vulnerability from July 2026 affected fully maintained sites that had simply been updated a few days too late. Anyone who does not want to monitor this themselves is better served by ongoing maintenance from €65 per month; cleanup is included in an emergency.
A virus does not get better on its own
The damage continues to grow regardless of the cost of the cleanup. A Google warning can only be removed slowly, a domain on a blocklist takes weeks to be removed, and every additional day gives those who have infiltrated the site time to quietly create a second and third access point. A call costs you nothing and takes five minutes.
Reachable Mondays to Fridays from 8 to 20 · Weekend appointments on request for a flat fee of 100 €
Technical background: Remove WordPress malware · Common cases: WordPress hacked, Site won't load, no longer able to log in · Overview: all topics and regions
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.