Customers tell you your website took them somewhere strange. You check, and it looks completely normal to you. You are not going mad. This kind of attack is built to hide from the owner and show itself only to visitors on phones, or only to people who arrive from Google. Here is how to prove it in two minutes, and how we remove it today for a flat $249.
Clean or your money back. Written. Flat $249, no hourly meter.
You do not need to know what your website is built with. We will tell you in the first 10 minutes.
Last updated · Reviewed by Ali Yasin Jatoi
If you ticked even one of these, send us the address of your website and we will look at it for free within the hour.
Take your phone. Open a private or incognito browsing window. Search Google for your business name, and click your own result rather than typing your address. If you land anywhere other than your own homepage, you have a redirect. Do the same on your laptop and it will very likely behave perfectly, because that is exactly what the attack is designed to do.
The code checks three things before it decides whether to redirect: whether you are on a phone, whether you arrived from a search engine, and whether you are logged in as an administrator. Owners are logged in and type their address directly, so owners see a healthy website. The person doing this is not trying to annoy you, they are trying to stay unnoticed for as long as possible, because they are paid per visitor delivered.
In the sites we clean, a redirect is almost never in one place. It sits in a few files at the top level of the website, in a settings table inside the database, and often in a small hidden add on that does not appear in any normal list. Deleting the one file you can find removes it for about a day. This is the single most common reason an owner tells us the problem came back.
Every person Google sends you is being handed to somebody else. Google notices quickly, drops your pages, and often adds a red warning screen on top, which then also frightens the visitors who did reach you. Two weeks of this can undo two years of search visibility, and recovery is far slower than the cleanup.
We request your website the way an attacker expects a real visitor to, from a phone and from a search result, and capture exactly where it sends people.
Full copy taken, then every place the redirect is triggered from is removed at once, files and database together, so it cannot reinstall itself.
Hidden admin accounts, scheduled tasks and add ons that nobody installed are all removed, and every password is rotated.
We ask Google to review the site, clean up any spam pages already indexed, and watch for 30 days in case a second copy is still waiting.
No quotes, no discovery calls, no hourly meter. You know the number before we touch anything.
One website, one price. Median clean time about 4 hours from the moment we have access. Written report at the end.
Everything above, plus locked down logins, file monitoring, and 60 days of reinfection cover.
Updates on staging, daily backups, monitoring, and a real engineer on call so this never repeats.
Clean or your money back. Written.
Two safe checks you can do before you call anyone, and one thing you should not do.
Stop and call us if: you are being told to edit a file called .htaccess or wp-config, or to run a find and replace across the database. A careless replace in a database breaks stored settings in a way that is much harder to undo than the redirect itself.
Because the code reads the visitor's device and only fires for phones. Phone visitors are worth more to the people running these campaigns and are far less likely to report it. It is a deliberate choice to keep the infection alive longer, not a glitch.
The code checks where the visitor came from. Traffic from a search engine is a stranger, so it gets redirected. Traffic that typed your address is probably you or a regular, so it gets your real homepage. Same reason: stay invisible to the owner.
Because the redirect had more than one home. There is usually a copy in the database and a scheduled task that rewrites the file if it goes missing. Until all three are removed at the same time, it will keep returning within a day or two.
Google will not punish you for being a victim, but it will stop trusting the pages while they send people elsewhere, and it may show a warning screen. Ranking damage is real and it grows with time, which is why we treat redirects as same day work rather than a queue job.
A flat $249 for a standard single website, including the report, the Google review request and 30 days of watching. If your site is a shop taking payments, we look for card stealing code at the same time and quote if it needs a deeper forensic job.
The redirect itself normally stops within the first hour. The full cleanup, meaning every way back in closed, takes about four hours from the moment we have access.
Occasionally, yes, and we check that first because it is free to rule out. A badly configured tracking script or an expired domain in an old plugin can look identical from the outside. If that is what it turns out to be, we tell you and you do not pay for a cleanup you did not need.
The twelve signs, in plain words.
What the warning means and how the appeal really works.
The engineer level breakdown, with the exact places we look.
Named malware types, process and evidence.