Remove the injected files. Rebuild the server if root was taken.
Unknown admins, a pharma redirect, a cron you did not add. Cleanup starts at €149. A miner or a new SSH key is not a plugin cleanup.
Users, files, cron. In that order.
A user created the night of the redirect. We remove it, rotate the salts and the database password, and check the web user cannot write wp-config.php.
PHP in uploads, a modified core file, a theme function that loads a remote script. Core is replaced from a clean copy. Uploads are not bulk-deleted.
A crontab under the web user, or a process that is not PHP. If the OS has a new UID 0 or an SSH key you did not add, cleanup of the site is the wrong job.
A rooted box is a rebuild
We say that after the first look, before billing a file-by-file clean of a host that will reinfect itself. Sites and mail come back from a copy that predates the break-in, onto a new server. That is quoted.
From €149 for a site. The OS is a different quote.
One WordPress install, files and users. Several sites, or WooCommerce with a large upload directory, is quoted after the size is known. We do not sell a “cleaned forever” guarantee. A nulled plugin will bring it back.
Redirect, warning in Search Console, or a user you did not create?
Tell us the host and what you saw. No admin password in the first message.
