Skip to main content
Claim your .com from $2.99 — free WHOIS privacy included

Learning Hub · Advanced · half a day, done right

How to Clean Up a Hacked Website

Full recovery — not just symptom removal — after a compromise — a practical, no-jargon walkthrough with the classic mistake flagged before you make it.

The short answer

Goal: full recovery — not just symptom removal — after a compromise. Time needed: half a day, done right. Difficulty: advanced.

The walkthrough below covers each step, the mistake most people make, and the shortcut worth knowing. On HostingAlly plans, several of the steps are handled for you — we note where.

Advanced

Difficulty

Quick

Time needed

5

Steps

24/7

Help if you're stuck

You don't need to be technical for this — the walkthrough is written for first-timers, tested against our own platform, and honest about which parts are genuinely fiddly versus merely unfamiliar.

Rule of the road: read the gotcha section before you begin, not after — it's harvested from the support tickets of people who didn't.

What you'll do, at a glance

The whole job breaks into clear stages: contain first, restore to a pre-compromise point, close the entry hole, sweep for persistence and rehabilitate externally.

Each stage is a few minutes of focused clicking — the elapsed time mostly depends on how familiar the control panel already feels. The detailed steps are listed further down this page; skim the whole route once before starting.

The classic gotcha

Restoring the newest backup — which was taken after the compromise and restores the infection with archival fidelity; the restore point must predate the breach, even at the cost of more lost content.

Forewarned is genuinely forearmed here — this exact mistake accounts for most of the frustration this topic produces, and it's entirely avoidable once named.

The tip we give everyone

Preserve a copy of the infected state before cleaning (zip it, download it) — if questions arise later (how they got in, what they touched), the evidence exists instead of having been helpfully destroyed.

It costs a minute now and repays it every time this task comes around again — which, like most hosting tasks, it will.

What's automated here

Several steps in this guide exist because hosting historically made you do them — on our plans, SSL issues itself, backups run daily without being asked, and one-click installers replace manual setup entirely. What remains is the genuinely-yours part of the task.

Stuck mid-task at an odd hour? That's what 24/7 human support is for — describe where you are in this guide and we'll take it from there.

Shield icon representing DDoS protection and site security

The platform this guide assumes

Tutorials age badly when they're written against imaginary hosting. These are written against ours — the same panel, installer and defaults you'll actually see.

NVMe storage and LiteSpeed caching are standard here, not premium-tier extras.

  • Step-by-step, tested as written
  • The gotcha flagged before you hit it
  • Automation covers the boring steps
  • 24/7 support if you get stuck

Why HostingAlly

What you get with every plan

No jargon tax

Terms are explained in place or linked to the glossary — nothing assumes you already know.

Help on standby

Stuck at step three at midnight? Support answers around the clock, mid-guide included.

Automation where it belongs

SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.

Written from real tickets

Our guides come from the support desk — the gotchas are the ones people actually hit.

The undo is always named

Where a step could bite, the guide says so and gives the reversal.

Works as written

Every step tested on our own platform — no 'your host may vary' hand-waving.

Getting Started

How to get going

  1. 1

    Contain first

    Maintenance-mode the site and change hosting, database and admin passwords immediately — cleanup during active attacker access is bailing with the tap running.

  2. 2

    Restore to a pre-compromise point

    The cleanest recovery is a backup that predates the breach — identify the intrusion window from file timestamps and logs, and restore behind it.

  3. 3

    Close the entry hole

    The vulnerable plugin, stolen credential or outdated component that admitted the attacker must be updated or removed — restoring without this schedules the sequel.

  4. 4

    Sweep for persistence

    Rogue admin users, unfamiliar files in uploads, modified .htaccess, planted forwarders — attackers leave return routes; the audit is what actually ends the incident.

  5. 5

    Rehabilitate externally

    Request review in Search Console if flagged, resubmit sitemaps, monitor for a fortnight — reputation recovery follows technical recovery.

Included

What's covered on our plans

  • Email accounts on your own domain
  • Free website migration handled by our team
  • Daily automatic backups with self-service restores
  • 24/7 support from real people
  • 99.9% uptime commitment, monitored around the clock
  • Per-site PHP version selection
  • SSH, Git and Composer access on developer-friendly plans
  • One-click installer for WordPress and 400+ apps
  • LiteSpeed server-level caching
  • No setup fees, ever

FAQ

Your questions, answered

Can I just run a cleaner plugin instead of restoring?

In-place cleaning is possible but demands expertise — malware hides in databases and legitimate-looking files, and missed persistence means recurrence. Restore-plus-patch is the reliable civilian path; in-place is for practitioners.

How do I find out how the site was hacked?

File modification times bracket the intrusion; access logs around that window show the requests; the targeted URL usually names the vulnerable component. It's honest detective work — and support can help read the logs.

Is SSL really included at no cost?

On every plan, with no exceptions — certificates are issued automatically when your domain points to us and renew themselves before expiry. The encryption is identical to paid DV certificates; paid tiers exist only for wildcard convenience or organisation-level validation.

Are backups included, and can I restore them myself?

Daily automatic backups are standard, restorable from the panel in minutes — files, databases or both, at 3am without a ticket if that's when you need it. For extra cover, you're welcome to run your own offsite copies alongside.

Do you include email with hosting?

Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.

Which control panel do you provide?

cPanel — the industry standard, which means every tutorial on the internet matches your screen, your backups restore anywhere cPanel runs, and skills learned here transfer for life. Plesk and DirectAdmin options exist on specific plans for those who prefer them.

Is there a money-back guarantee?

Yes — try the hosting properly and if it doesn't fit, the refund process is a request, not a retention gauntlet. Domain registrations are the one standard carve-out, since registries make those non-refundable the moment they're placed.

Launch it properly this time.

From your first site to a fleet of servers, the upgrade path is an account change, not a migration.

See Hosting Plans