What does a website malware removal service actually do?

A proper malware removal service does three things: it removes every malicious file, database entry and account, it finds and closes the way the attacker got in, and it removes the persistence that would let them back. Deleting the visible malware on its own is not a clean-up; it is a pause before the next infection.

Most infections we investigate have several layers. The part the site owner notices, such as a redirect or a spam page, is the payload. Underneath it there is usually a webshell or backdoor that delivered the payload, and often a scheduled task or rogue user that reinstalls the backdoor if it is removed. A one-off file clean that misses these layers is why so many sites are "fixed" and then re-infected within days.

PatientZero works at the server level, not just inside WordPress. That matters because many backdoors live outside the web root, in crontabs, systemd services or files disguised as system binaries, where a WordPress security plugin cannot see them. You can read more about this difference in our guide to security plugins versus server-side scanning.

How PatientZero removes malware, step by step

We start with evidence, not deletion. The platform connects to your server over SSH, deploys the scan engine to /opt/patient-zero/scan-engine, and runs a forensic scan across every site on the server before anything is changed. That gives us a record of what was there and a timeline of how it arrived.

  1. Triage and containment. We confirm the symptoms, take a snapshot for forensics and, if customers are at risk, put up a holding page.
  2. Forensic scan. The dfir-fast profile looks for indicators of compromise: recently modified PHP, suspicious cron entries, unexpected users, listening processes and known webshell kits.
  3. Malware sweep. The malware-intelligence profile checks every file and database against signatures and heuristics for obfuscated code, injected scripts and SEO spam.
  4. Clean. Malicious files are quarantined with hashes recorded in the evidence vault. Core files are restored from clean sources, and database spam and rogue options are removed.
  5. Root cause. We identify the entry point, for example a vulnerable plugin, a leaked password or an exposed service, and fix it.
  6. Harden and verify. Harden playbooks are applied, credentials are rotated and every site is checked back online.

Everything we remove or restore is written to the Activity log, and you receive a report you can share with clients, insurers or, if personal data was involved, the ICO.

Which infections do we remove?

We remove the full range of website and server malware we see in real incidents, from front-end symptoms such as redirects and SEO spam to server-level compromises with reverse shells and hidden VPN nodes. The table below summarises the common types and where each one usually hides.

InfectionWhat you seeWhere it usually hides
Redirect hackVisitors sent to scam or spam sitesInjected JavaScript, .htaccess, wp_options
Pharma / Japanese keyword hackSpam pages in Google resultsCloaking code in theme files, generated pages, rogue Search Console owners
Webshell / backdoorMalware returns after cleaningUploads folders, fake plugin files, cron jobs
Card skimmerCustomer card fraudCheckout templates, database-stored scripts
CryptominerHigh CPU, slow serverFake system binaries, systemd services
DefacementHomepage replacedIndex files, theme templates

Each of these has its own page with more detail: WordPress malware removal, hacked website repair, Google blacklist removal, server malware removal and WooCommerce card skimmer removal.

What does unlimited malware removal mean?

Unlimited malware removal means that while you are on a PatientZero plan, any re-infection is cleaned at no extra cost. There is no per-incident fee and no cap on the number of clean-ups. You pay a monthly subscription, with no contract, and can cancel any time.

We price it this way because the incentive should be the same on both sides: we want your site to stay clean. Every clean-up is followed by hardening and 24/7 monitoring, so re-infections are rare, and if one does happen we treat it as a signal that something was missed and investigate again.

  • Single Site: £99/month plus a one-off £129.99 security audit and setup
  • Server / Multi-site: priced on application, covering every site on the server
  • Agency (white-label): from £299/month
  • Fair use applies to full server rebuilds

The one-off audit exists so we know exactly what we are cleaning before the first removal. See pricing for full plan details.

What should you do if your website is infected right now?

Do not start deleting files. Change your hosting, SSH and WordPress admin passwords from a device you trust, take a full backup snapshot so the evidence is preserved, and note down what you saw and when. Then contact us, or start emergency triage, and we will take it from there.

Taking card payments? If you suspect a card skimmer, tell us straight away. Payment data exposure can bring reporting obligations, and speed matters.

If you are not sure whether you are infected, start our two-minute security triage and we will tell you what to do next. Remember that a clean public check does not mean a clean server: most malware hides server-side, which is why we run a full forensic scan. If it is urgent, go straight to emergency help or call 01932 593642.