What does a website malware removal service actually do?
A proper malware removal service does three things: it removes every malicious file, database entry and account, it finds and closes the way the attacker got in, and it removes the persistence that would let them back. Deleting the visible malware on its own is not a clean-up; it is a pause before the next infection.
Most infections we investigate have several layers. The part the site owner notices, such as a redirect or a spam page, is the payload. Underneath it there is usually a webshell or backdoor that delivered the payload, and often a scheduled task or rogue user that reinstalls the backdoor if it is removed. A one-off file clean that misses these layers is why so many sites are "fixed" and then re-infected within days.
PatientZero works at the server level, not just inside WordPress. That matters because many backdoors live outside the web root, in crontabs, systemd services or files disguised as system binaries, where a WordPress security plugin cannot see them. You can read more about this difference in our guide to security plugins versus server-side scanning.
How PatientZero removes malware, step by step
We start with evidence, not deletion. The platform connects to your server over SSH, deploys the scan engine to /opt/patient-zero/scan-engine, and runs a forensic scan across every site on the server before anything is changed. That gives us a record of what was there and a timeline of how it arrived.
- Triage and containment. We confirm the symptoms, take a snapshot for forensics and, if customers are at risk, put up a holding page.
- Forensic scan. The
dfir-fastprofile looks for indicators of compromise: recently modified PHP, suspicious cron entries, unexpected users, listening processes and known webshell kits. - Malware sweep. The
malware-intelligenceprofile checks every file and database against signatures and heuristics for obfuscated code, injected scripts and SEO spam. - Clean. Malicious files are quarantined with hashes recorded in the evidence vault. Core files are restored from clean sources, and database spam and rogue options are removed.
- Root cause. We identify the entry point, for example a vulnerable plugin, a leaked password or an exposed service, and fix it.
- Harden and verify. Harden playbooks are applied, credentials are rotated and every site is checked back online.
Everything we remove or restore is written to the Activity log, and you receive a report you can share with clients, insurers or, if personal data was involved, the ICO.
Which infections do we remove?
We remove the full range of website and server malware we see in real incidents, from front-end symptoms such as redirects and SEO spam to server-level compromises with reverse shells and hidden VPN nodes. The table below summarises the common types and where each one usually hides.
| Infection | What you see | Where it usually hides |
|---|---|---|
| Redirect hack | Visitors sent to scam or spam sites | Injected JavaScript, .htaccess, wp_options |
| Pharma / Japanese keyword hack | Spam pages in Google results | Cloaking code in theme files, generated pages, rogue Search Console owners |
| Webshell / backdoor | Malware returns after cleaning | Uploads folders, fake plugin files, cron jobs |
| Card skimmer | Customer card fraud | Checkout templates, database-stored scripts |
| Cryptominer | High CPU, slow server | Fake system binaries, systemd services |
| Defacement | Homepage replaced | Index files, theme templates |
Each of these has its own page with more detail: WordPress malware removal, hacked website repair, Google blacklist removal, server malware removal and WooCommerce card skimmer removal.
What does unlimited malware removal mean?
Unlimited malware removal means that while you are on a PatientZero plan, any re-infection is cleaned at no extra cost. There is no per-incident fee and no cap on the number of clean-ups. You pay a monthly subscription, with no contract, and can cancel any time.
We price it this way because the incentive should be the same on both sides: we want your site to stay clean. Every clean-up is followed by hardening and 24/7 monitoring, so re-infections are rare, and if one does happen we treat it as a signal that something was missed and investigate again.
- Single Site: £99/month plus a one-off £129.99 security audit and setup
- Server / Multi-site: priced on application, covering every site on the server
- Agency (white-label): from £299/month
- Fair use applies to full server rebuilds
The one-off audit exists so we know exactly what we are cleaning before the first removal. See pricing for full plan details.
What should you do if your website is infected right now?
Do not start deleting files. Change your hosting, SSH and WordPress admin passwords from a device you trust, take a full backup snapshot so the evidence is preserved, and note down what you saw and when. Then contact us, or start emergency triage, and we will take it from there.
Taking card payments? If you suspect a card skimmer, tell us straight away. Payment data exposure can bring reporting obligations, and speed matters.
If you are not sure whether you are infected, start our two-minute security triage and we will tell you what to do next. Remember that a clean public check does not mean a clean server: most malware hides server-side, which is why we run a full forensic scan. If it is urgent, go straight to emergency help or call 01932 593642.