Sound familiar?
- A security scanner or your host reports malware on your site
- Unknown PHP files in uploads, cache or image folders
- Spam links or hidden text in your page source
- The site redirects some visitors elsewhere
- Server CPU usage spikes with no rise in visitors
- Your domain's email is being blocked for spam
Key facts
- Both files and database scanned and cleaned
- Core files verified against official checksums and replaced
- Backdoors, web shells and malicious cron jobs removed
- Card skimmer checks on WooCommerce, Magento, PrestaShop and OpenCart
- Blocklist and Google Search Console review requests handled
- £45 an hour + VAT or quoted; monitoring from £25 a month + VAT
Types of website malware we remove
- Backdoors and web shells: small scripts that let attackers back in after you clean up. They hide in plugin folders, uploads, fake image files and even legitimate-looking core files.
- SEO spam: thousands of pages or hidden links for pharma, casino or counterfeit goods, often only shown to search engine crawlers. Also called the Japanese keyword hack.
- Malicious redirects: code that sends visitors, often only on mobile or on their first visit, to scam sites. Usually injected into JavaScript files, .htaccess or database options.
- Card skimmers: JavaScript on checkout pages that copies payment details as customers type them.
- Cryptominers and spam mailers: scripts that use your server's resources or send spam from your domain, getting the host to suspend you and your email blocklisted.
Our malware removal process
- Snapshot: copy the infected site so evidence is kept and nothing is lost.
- Scan files: compare core files to official checksums (for WordPress, wp core verify-checksums), search for obfuscation patterns such as eval(, base64_decode, str_rot13 and preg_replace with the /e modifier, list recently modified files and look for PHP in folders that should only hold images.
- Scan the database: search posts, options, widgets and config tables for injected <script> tags, iframes and encoded payloads. On Magento we check core_config_data, a common skimmer hiding place.
- Check the server: cron jobs, .htaccess and .user.ini files, and other sites in the same hosting account that could reinfect yours.
- Remove and replace: delete malicious files, replace core and plugins with clean copies, clean the database.
- Patch and reset: update the vulnerable component and reset every password and secret key.
- Verify: rescan, check the site as a search engine and mobile visitor, and request reviews from Google and other blocklists.
Why automated scanners are not enough
Security plugins and host scanners are useful for spotting infections, but they often miss obfuscated backdoors and database injections, and some "clean" by deleting files, which can break the site. Others clean the visible symptoms while the backdoor remains, so the infection returns days later.
Manual review alongside scanning finds what tools miss. It also tells you how the attacker got in, which is the only way to stop it happening again. Patchstack's State of WordPress Security report found 46% of WordPress vulnerabilities disclosed in 2025 had no patch available at disclosure, so sometimes the right fix is removing a plugin entirely rather than waiting for an update.
Email and reputation clean-up
If malware was sending spam, your server's IP or domain may be on email blocklists, and customers may stop receiving your emails. After cleaning, we check major blocklists, request delisting where appropriate and make sure SPF, DKIM and DMARC records are in place. See email deliverability. If your site was flagged in Google, see hacked website repair for the review process.
Shared hosting and cross-contamination
One of the most common reasons a cleaned site gets reinfected is another site in the same hosting account. Many businesses have an old test site, a forgotten microsite or an abandoned WordPress install in a subfolder. If any of those is infected, it can rewrite files in your main site because they run as the same user.
We list everything in the hosting account, clean or remove old installs, and recommend separate accounts or isolated hosting for sites that must stay. If your host cannot isolate sites from each other, that is worth knowing. See abandoned website support for old sites nobody looks after.
Prices
Malware removal is £45 an hour + VAT, with a 30-minute minimum then 15-minute blocks. Heavily infected sites, or hosting accounts with many infected sites, are quoted after an initial assessment. To keep the site clean afterwards, our Essential plan at £25 a month + VAT includes updates applied and checked, daily off-server backups, uptime monitoring and security monitoring. See website security or get in touch.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
How much does website malware removal cost?
dijitul charges £45 an hour + VAT for malware removal, with a 30-minute minimum then 15-minute blocks. Badly infected sites or hosting accounts with many sites are quoted after an initial assessment.
Will a security plugin remove malware for me?
Sometimes, but plugins often miss obfuscated backdoors and database injections, and may delete files in ways that break the site. dijitul combines scanning with manual review to remove malware and find how it got in.
Why does malware keep coming back after I remove it?
Usually because a backdoor was missed or the original vulnerability was never fixed. Another infected site in the same hosting account can also reinfect yours. dijitul checks the whole hosting account and patches the entry point.
Can malware on my website affect my email?
Yes. Malware that sends spam can get your server IP or domain blocklisted, so legitimate emails bounce or land in spam. dijitul checks blocklists, requests delisting and fixes SPF, DKIM and DMARC records.
How do I check my online shop for a card skimmer?
Look at checkout page source for unfamiliar external scripts and check the database for injected JavaScript. Skimmers are often hidden and only load on checkout. dijitul checks WooCommerce, Magento, PrestaShop and OpenCart shops for them.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.