Website redirects to a strange site
Redirects of this kind are deliberately designed so that the operator does not notice them for as long as possible. They only take effect for visits from the search engine, only on mobile devices and only for visitors who are not logged in.
That is why everything looks normal on your own computer, while your customers end up somewhere else.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
Why you do not notice it yourself
The code checks who is accessing the page before every response. Four conditions are common.
Only from the search engine
The redirect only takes effect when the visit comes from Google. Anyone who enters the address directly sees the normal page.
Only on mobile devices
Everything remains unchanged on desktop. Since operators usually check their website on a computer, the infection remains undetected for a long time.
Not for logged-in users
As long as you are logged in to WordPress, the redirect is skipped. That is precisely why the backend appears completely unobtrusive.
Only once per visitor
A cookie ensures that the redirect does not occur on the second visit. Anyone who wants to report it often cannot reproduce it.
How the redirect is removed
Reproduce the trigger
I access the site under the same conditions as an affected visitor and record the server's response. This establishes exactly where the redirect occurs.
Find the source in the code
The redirect is located in the .htaccess file, the theme, a plugin, or directly in the database. All four locations are checked, not just the first hit.
Remove and re-check
After removal, it is tested again under all conditions, including on mobile and via search. Only then is the site considered clean.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
Frequently asked questions
I can’t see the redirect. Is my site still affected?
This is the usual case with this type of infection. It can be checked by accessing the site on a phone via a search result, ideally in a private window and without logging in. This can only be reliably clarified on the server.
Is it enough to replace the .htaccess file?
Only if the redirect is located there exclusively. It is often also stored in the database or a theme file, and then it comes back after a short time.
How does this affect my ranking?
Google downgrades such pages and in many cases displays a warning. After cleanup, I request a new review, which usually takes one to three days.
Every day with an active redirect costs customers
A call costs you nothing and takes five minutes. If it turns out to be a different problem, I will tell you that too.
Available Monday to Friday from 8 a.m. to 8 p.m. · Related topics: Google warns about your website · Strange subpages in the Google index · Remove WordPress malware · Remove WordPress virus
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.