Site Rescue: Hack, Malware and Slowdown Clean-up | Abdul Rehman
Site rescue · 1–3 days · Written report

Your site is broken, flagged or hacked. I clean it and tell you exactly what changed.

This is the one job where waiting costs money every day. While a browser is warning visitors away, or a form is silently failing, enquiries are going to whoever is easier to reach.

Does any of this sound familiar?

If you can point at one of these, the problem is real and usually fixable in a day or two.

  • Chrome, Safari or your host is showing a security warning on your own domain
  • Google Search Console says the site is hacked, or results now say "this site may be compromised"
  • Your host suspended the account or emailed you about malicious files
  • Google traffic fell off a cliff and nobody can explain why
  • The site takes 8–15 seconds to load and feels heavier every month
  • The contact form submits but no confirmation arrives, and enquiries went quiet
  • The layout breaks on a phone, where most of your visitors are
  • A previous developer or another provider left mid-job and things are half-finished

What actually happens

1

Find it

I take a full copy of the site and look through it. Infected files, backdoors, modified core files, unexpected admin users, and the entry point the attacker actually used.

2

Remove it

Malicious files deleted, injected code stripped out, unused and abandoned plugins and themes removed, and the entry point closed so it does not simply happen again next week.

3

Harden it

Passwords and salts rotated, admin access locked down, file permissions corrected, updates applied, and the settings that stop the common attacks switched on.

4

Explain it

You get a written report: what was found, what was changed, what to watch for, and what to do differently. If Google needs to re-review the site, I tell you how to request that.

Two levels, priced up front

Contained problem

$299 – $499

  • One site, one clean-up pass
  • Infected files identified and removed
  • Core files and admin users checked
  • Hardening and updates applied
  • Written report of what changed
  • Typically finished inside 48 hours

Deep infection or repeat incidents

$499 – $899

  • Everything in the contained band
  • Multiple infected sites on the same hosting account
  • Attacker still has access, or the site was reinfected after a previous clean-up
  • Blacklisting, or a host suspension to resolve
  • Google re-review support
  • Written report plus a prevention plan

The exact figure is confirmed in writing before I start, after I have looked at the site. If the problem turns out to be something else, I tell you before doing anything.

Why trust this particular job

I have run this on my own site. In October 2026 an attacker injected an obfuscated loader into my homepage and dropped three additional backdoors into the file system, including one disguised as a WordPress security plugin. I quarantined every file, preserved SHA-256 hashes, wrote up exactly how each one worked, and hardened the server afterwards.

That investigation is why this page exists. Removing a backdoor is not a plugin install — it is reading someone else's deliberately confusing code and proving you got all of it.

What I need from you

  • Access to the hosting account, or a full backup of the site
  • What you first noticed, and roughly when
  • Anything your host has already told you
  • Whether you have a recent clean backup — if so, that often saves a day

Included either way

A written scope and fixed price before work starts, a 50% deposit and the balance on delivery, a 14-day fix guarantee on my work, and an NDA on request. If your site holds customer data, say so up front and I will tell you plainly whether this is a job for me or for a managed security vendor.

Tell me what you are seeing.

Send the domain and the symptom. I will look at it and reply with what I think is wrong, a fixed price, and a start date — usually within a few hours.

WhatsApp Send a message Book a 15-minute call