Website Security, Malware Removal & Recovery.
If your site is already compromised, start with an email — we'll pick up the same day. If it isn't yet, we'll audit the obvious holes, harden the stack, and set up monitoring so the next suspicious login surfaces in a report, not a customer complaint. We've cleaned enough kalabynidhi-style hacks to know what actually works.
A short list of
real things.
Not deliverables in the consultant sense. Actual files, pages, docs, access. Listed here so there's no surprise.
- 01Incident triage — identify whether the site is actively compromised, and how badly
- 02Full-site malware scan (file-level + database-level), isolated in a clean environment
- 03Removal of injected code, malicious admin users, rogue cron jobs, and backdoor uploads
- 04Credential rotation: admin passwords, FTP/SFTP, database, hosting panel, WP salts
- 05Hardening: file permissions, wp-config lockdown, disabling file editor, 2FA, login attempt limits
- 06Plugin & theme audit — remove abandoned/nulled plugins, update the rest to known-good versions
- 07SSL / HTTPS review, security headers (CSP, HSTS, X-Content-Type-Options)
- 08Google Search Console review — request reconsideration if the site was blacklisted or flagged
- 09Written post-incident report: what was found, how it got in, what was changed
- 10Monitoring set up: file-integrity, login alerts, and a monthly check-in
Four principles.
No slogans.
Cleanup before hardening
You can't harden a site that still has a backdoor in it. We take the site offline or behind a maintenance page, clean everything in an isolated environment, then bring it back — not the other way around.
The hole is usually not what you think
Most compromises aren't zero-days — they're an outdated plugin, a weak admin password, or a nulled theme someone installed two years ago. We find the actual entry point and fix that, not the symptom.
Monitoring you'll actually read
Wordfence emailing you 400 'possible attack' notifications a week trains you to ignore the one that matters. We tune alerts so the only thing that reaches your inbox is worth looking at.
Assume it'll happen again
A hardened site is lower-risk, not zero-risk. We set up backups you can actually restore from, and document the recovery playbook — so the next incident is a one-hour event, not a one-week event.
How we work, start to finish.
- 01Triage (hour 0)
You email hello@genvoid.com, we reply same day with a scoped response — what we need (hosting credentials, last-known-good timeline, any hosting tickets) and what we'll do first. Nothing touches the site until you've signed off on access.
- 02Clean environment (hour 1–12)
We pull a full site copy into an isolated environment, run file-level and DB scans, and manually review every recent change. You get a written list of what we found before anything is deleted.
- 03Cleanup & hardening (hour 12–24)
Injected code removed, malicious accounts purged, credentials rotated, plugins audited, security headers set, backup/monitoring configured. Site goes back online once the scans come back clean.
- 04Post-incident report
Written report: what we found, how it got in, what we changed, what we recommend for the next 6 months. Plus a reconsideration request filed with Google if the site was flagged.
Response times we commit to.
These are the response windows we work to on active incidents — measured from your first email. Not SLA-theatre: the numbers we actually hit.
Before you
ask us.
Send the URL. We'll pick up today.
For an active incident: email hello@genvoid.com with the URL and what you know. We'll reply same day with a triage plan. For a preventive audit: book a consultation and we'll walk through the stack.
or email hello@genvoid.com