Red Flags When Hiring a Malware Removal Service
By Glenn Lyvers · Updated · 4 min read
You are stressed, your site is down or flagged, and you are about to hand your server credentials to a stranger you found in a search result twenty minutes ago. That is a bad combination, and plenty of operations are built specifically around it. Here is how to tell the difference between someone who will actually fix this and someone who will run a scanner and send an invoice.
Manufactured urgency
Your situation is genuinely urgent. That does not mean the person you hire should be adding to the pressure. Be wary of anyone who tells you the damage is compounding by the minute, that a limited-time price expires today, or that your data is being actively exfiltrated as you speak without having looked at anything.
A professional will tell you what is time-sensitive and what is not — a live card skimmer genuinely is, a spam injection mostly is not — and will be comfortable with you taking an hour to decide. Urgency used as a closing technique is a sales tactic, and it usually indicates where the operation's actual expertise lies.
Guarantees that cannot be kept
A guarantee that your site will never be hacked again is not a guarantee, it is a marketing line, and nobody who understands this work would offer it. Security is not a state you achieve permanently. What can reasonably be promised is that this infection will be removed, that the entry point will be identified where the evidence permits, and that reinfection from the same cause will be covered for some defined period.
Similarly, treat promises about search rankings with scepticism. A cleanup removes the cause of a warning or penalty; nobody controls how quickly Google re-crawls or exactly what position you return to. My guide on ranking recovery covers what is actually predictable.
A scan sold as a cleanup
This is the most common way people waste money. An automated scan finds known signatures in files, and that is genuinely useful as a first pass. It is not a cleanup. It routinely misses database-resident malware, mu-plugins backdoors, scheduled task persistence, and injections that live in plugin settings rather than in files.
The question that separates them: ask what they check beyond a file scan. If the answer does not include the database, the scheduled tasks, the user accounts and the server configuration, you are buying a scan. My guide on why free scanners miss backdoors covers the gap in detail.
No interest in how it happened
This is the single most reliable signal, and it is the one most people do not think to check. If nobody asks about your logs, your update history or your recent changes, and nobody tells you afterwards how the attacker got in, then the entry point was never investigated — which means it is still open.
A site cleaned without closing the way in gets reinfected, and at that point you are offered another cleanup. Whether that cycle is incompetence or a business model varies. Either way, ask up front whether identifying the entry point is part of the work, and ask afterwards what they found.
Other things worth noticing
No contact detail beyond a form, or a company with no identifiable people behind it. Pricing that cannot be explained, or a quote given before anyone has looked at the site — a range is reasonable, a precise figure sight-unseen is a product rather than a service. Requests for your credentials through insecure channels. Pressure to buy an annual plan before the emergency is resolved.
And be careful with unsolicited contact. A cold email telling you that your site is hacked may be accurate, or it may be a sales tactic aimed at everyone, or it may be outright extortion — my guide on fake hacked-site emails covers telling them apart before you panic.
What to ask
Five questions, and the quality of the answers tells you nearly everything. Will you identify how the site was compromised? Do you check the database as well as the files? What will you give me at the end — will I get a report of what was found and removed? What happens if it comes back? And do I need to give you credentials, or can you work from access I control and can revoke?
Clear, specific answers to those are a good sign. Evasion, or an immediate pivot to a monthly plan, is not. My guides on what a cleanup report should contain and choosing a cleanup path cover the rest of the decision — and if you want to see what a straight answer looks like, that is how I work on my own malware removal service.
Common questions
Is a guarantee against future hacks realistic?
No. Nobody can promise a site will never be compromised again, and offering that says more about the seller than the service. What is reasonable is a guarantee that this infection is removed and that reinfection from the same cause is covered for a defined period.
How can I tell a real cleanup from an automated scan?
Ask what gets checked beyond files. A real cleanup covers the database, scheduled tasks, must-use plugins, user accounts and server configuration, because that is where persistence hides. If the answer is only about scanning files for known signatures, you are buying a scan.
Why does identifying the entry point matter so much?
Because a clean site with an open door gets reinfected, usually within days. If nobody investigates how the attacker got in, nobody closes it. It is the difference between fixing the problem and removing the symptom, and it is the clearest way to judge whether someone is serious.
Should I be worried about giving out my credentials?
You should be careful about how. Use access you can revoke, create a separate account rather than sharing your own where possible, send credentials through a secure channel rather than email, and change everything afterwards. A professional will expect all of that and will often suggest it themselves.
I got an email saying my site is hacked. Is it genuine?
It might be, but treat it as unverified. These range from legitimate notifications through cold sales outreach sent to everyone, to extortion attempts based on nothing. Verify independently by checking your own site and Search Console before responding or paying anybody anything.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.