Website Malware Removal: What to Do When Your Site Is Hacked
Website malware removal, step by step: confirm the hack, preserve evidence, restore a clean copy, and lock down the accounts that matter.
By Matthew Zhao · Editor, Hosted EZ

Website malware removal is careful cleanup work, not a race through the control panel. The right approach is to confirm the infection, preserve the evidence, and restore from a known-good copy before you call it finished. It is tempting to click through settings until the problem appears to move. That usually creates a second problem with less evidence.
This guide focuses on the site cleanup steps a small-site owner can take safely. It also points out where a host, registrar, email provider, or developer needs to take over. Read how to choose a web host if you need the broader setup, and our guide to migrating without downtime before changing live infrastructure.
Start with a clear inventory
Protect the account that can change DNS, billing, and server access first. Use a unique password and multi-factor authentication where it is available. A hacked website often traces back to a stolen control-panel login, and an application update cannot compensate for one.
Make a short note with account names, domain names, the exact URL involved, and the last known working time. Do not put passwords or recovery codes in the note. You want enough detail to retrace the work without creating a new security risk.
Website malware removal starts from a clean copy
Keep backups outside the production account and practice a restore. Malware removal usually ends with restoring a copy from before the infection, and a backup that has never been opened is a hope, not a recovery plan.
Use a private browser window or a separate device after a change. That removes some of the confusion caused by cookies and cached redirects. If a DNS record is involved, note the TTL and allow the old answer time to expire before assuming the change failed.
Test the result like a visitor
When you find malware, preserve the evidence, restrict access, and work from a known-good copy. Avoid making a string of unexplained changes that destroy the trail you need to understand how the site was compromised.
Test the normal path first, then the part that has the most consequence. For a store, that is checkout. For a form, it is receiving the email. For a cleanup, it is confirming the injected files and redirects are gone. A test should answer one question rather than produce a vague impression.
When to stop and ask for help
Stop when the next action could overwrite data, change production mail, or remove access to the account. Send support the domain, time in UTC, exact error, and the changes you made. Include a screenshot when it shows the error, but do not include private keys, passwords, or full payment information.
Let's Encrypt documentation has useful background on the standards behind this topic: Let's Encrypt documentation. Use it to understand the terms, then return to the small, reversible next step.
A sensible maintenance habit
Put the final configuration and the result of the website malware removal in a short maintenance note. Hosting problems repeat because nobody remembers which account owns a record or which plugin was disabled last time. A dated note turns the next incident into a lookup instead of an investigation.
Keep the change auditable
Use a short before-and-after record. Write the setting you found, its old value, the exact time you changed it, and the result of the test. If the change has a delay, such as a DNS TTL or a cache expiry, write the time you expect the new answer to be visible. This record is useful even when everything works. A few months later, it tells you why a setting has an unusual value.
Do not confuse an account dashboard with evidence from the live site. A dashboard can show that it accepted a record or a deployment. The visitor still needs to receive the page, email, redirect, or certificate you intended. Test from outside the account, and use a second connection if a cached answer could mislead you.
If you hand the task to someone else, give them the record rather than a conclusion. "The site is slow" is hard to investigate. "The delay began after this update, affects this URL, and persists in a private window" gives the next person a useful starting point.
One last check
Before you close the ticket or move to the next task, repeat the action that prompted the change. Use the ordinary path a visitor or colleague would use, not only the account dashboard. If the result is different, note the difference and keep troubleshooting from that point. A quiet confirmation now is much easier than discovering the missed detail during a launch or an outage.
Leave a useful handoff
Save the final test result with the date and account involved. If someone else needs to revisit the work, they should be able to see what changed without reconstructing the whole incident from browser history.
Bottom line
Website malware removal gets easier when you preserve the evidence, work from a known-good copy, and test the result where it matters. Keep backups outside the account, protect your logins, and ask support before a cleanup step turns into a data-loss risk.
Frequently asked questions
Do I need to fix a hacked website all at once?
No. Change one related setting, test it, and keep the previous value until you know the result is stable.
What should I tell hosting support after a hack?
Give the domain, exact URL or service, UTC time, error text, and steps already tried. That is usually enough for support to find the relevant logs.
Do I need a backup before site cleanup?
Yes. Download or verify a recent backup before edits that affect files, databases, email, DNS, or software versions.
About the author
Matthew Zhao
Matthew has spent his career running production server fleets — tens of thousands of machines' worth. He writes about hosting the way he wishes someone had explained it to him: plainly.
About Hosted EZ →Get the next guide in your inbox
One email when we publish something worth your time. No spam, unsubscribe whenever.


