The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Intermediate & Advanced SEO
    4. Looking for someone to help with a delisted site after a malicious hack

    Looking for someone to help with a delisted site after a malicious hack

    Intermediate & Advanced SEO
    6 3 116
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • musillawfirm
      musillawfirm last edited by

      Hello,

      My website - www.musillawfirm.com was recently hacked and has been de-listed by google. It had some sort of a crypto mining script on it that I was able to remove.  It shows up if you type in the domain but even a generic search for "musil law firm" does not show the site - it used to rank # 1 for that term and #1 or 2 for immigration lawyer in my local area.  If anyone can assist me in getting it re-indexed please let me know and let me know how much it would cost.  I tried getting it re-indexed through the search console, but no luck.

      Thank you kindly

      1 Reply Last reply Reply Quote 0
      • Roman-Delcarmen
        Roman-Delcarmen last edited by

        If you have been hacked probably Google put you on a blacklist. So, in that case, you need to clean up your site, and then request an evaluation process on Google. You will need to explain what happened, and what did you about it. I have a case like this a year ago.

        Once they make sure you are a secure site, then you will visible again. I try to enter to your website and the firewall is blocking your site.

        URL: http://www.musillawfirm.com/
        Category: Malicious Websites

        So, in that case, your site is still insecure or still is on a blacklist or even both.

        1 Reply Last reply Reply Quote 3
        • Roman-Delcarmen
          Roman-Delcarmen last edited by

          I made an audit and your situation does not look ok.

          http://www.musillawfirm.com/
          Virus: HTTP
          Virus: SmallHTTP
          Virus: W32/Http.FILESHARE
          Virus: W32/HTTP.A!dos
          Virus: W32/Kryptik.WWW
          Virus: VBS/Doget.HTTP!tr.dldr
          Virus: Riskware/TinyHTTP
          Virus: W32/NukeHTTP.A!tr

          The Fortinet Anti-Virus Analyst Team is currently in the process of creating a detailed description for this virus.

          HOPE THIS INFO CAN HELP YOU

          1 Reply Last reply Reply Quote 3
          • musillawfirm
            musillawfirm last edited by

            Thank you!  How do I remove it? And how do I ask google to take me off the blacklist?

            Thank you

            Roman-Delcarmen 1 Reply Last reply Reply Quote 0
            • Roman-Delcarmen
              Roman-Delcarmen @musillawfirm last edited by

              Ok this is, not a simple process

              STEP - 1 Review Warning Status

              Your website is blacklisted because Google scanned your site and found harmful behavior. Google needs to protect its users from dangerous websites that show up in their search results. In fact, websites that repeatedly get blacklisted for malicious behavior are limited to only one review every 30 days. That big red splash page (and warnings next to your site in Google's search results) are designed to stop visitors from entering your site. It works, too. Websites lose about 95% of their traffic when blacklisted by Google.

              The specific warning message on your site can help you to understand what Google is telling you about the type of security issues they found on your site. This information will be useful in the following sections of this guide.

              Here are a few examples of common malware warnings that suggest your hacked website is serving malicious downloads such as viruses, spyware, rootkits, and ransomware. Most browsers use Google's blacklist API, but Microsoft (IE/Edge) have their own. The following images are examples of this kind of blacklist warning from popular browsers.

              • Website Malware Warnings
              • Website Phishing Warnings

              So the first step is to identify which one is your problem

              STEP - 2 Fix Blacklist Symptoms

              If you use a CMS such as WordPress or Joomla, you can safely rebuild the site using fresh copies of your core files and extensions directly from the official repositories. Custom files can be replaced with fresh a recent backup, as long as it's not infected.

              To manually remove a malware infection from your website files:

              1. Log into your server via SFTP or SSH.
              2. Create a backup of the site before making changes.
              3. Search your files for any reference to malicious domains or payloads you noted.
              4. Identify unfamiliar or recently changed files.
              5. Restore suspicious files with copies from the official repository or a clean backup.
              6. Replicate any customizations made to your files.
              7. Test to verify the site is still operational after changes.

              To manually remove a malware infection from your database tables:

              1. Log into your database admin panel.
              2. Make a backup of the database before making changes.
              3. Search for suspicious content (i.e., spammy keywords, links).
              4. Open the table that contains suspicious content.
              5. Manually remove any suspicious content.
              6. Test to verify the site is still operational after changes.
              7. Remove any database access tools you may have uploaded.

              To clean up your user accounts:

              Confirm all website user accounts are valid:

              1. CMS users
              2. FTP/SFTP/SSH users
              3. Database administration panels (PHPMyAdmin, etc.)
              4. cPanel accounts
              5. Hosting company logins
              6. Change all passwords for all users.
              7. Enable two-factor-authentication (2FA) if it is available.

              Backdoors commonly include the following PHP functions:

              1. base64
              2. str_rot13
              3. gzuncompress
              4. eval
              5. exec
              6. create_function
              7. system
              8. assert
              9. stripslashes
              10. preg_replace (with /e/)
              11. move_uploaded_file

              Step 3 Final Steps

              To remove the blacklist warning you need to let Google know that you have completely cleared the infection. To do this, you must have a Google Search Console account (formerly Webmaster Tools).

              To verify ownership of your website in Google Search Console:

              1. Open Google Webmaster Central.
              2. Click Search Console and sign in to your Google account.
              3. Click Add a site.
              4. Type in your site's URL and click Continue.
              5. Verify your site using the Recommended method or Alternate methods options.
              6. Click Add a site.
              7. Click Verify.
              8. Check the Messages section to review any warnings.

              _NOTE: THIS JUST A GUIDE BASED ON MY EXPERIENCE, KEEP IN MIND THAT SOME THINGS CAN BE VALID TO YOUR CASE AND OTHERS WILL NOT VALID, ALL DEPENDS ON YOUR CMS, YOUR SERVER CONFIGURATION AND I CAN NOT GIVE YOU A EXACT ADVICE WITHOUT SPECIFIC INFORMATION _

              IF THE ANSWER WERE USEFUL DONT FORGET TO MARK IT AS A GOOD ANSWER 🙂

              GOOD LUCK

              1 Reply Last reply Reply Quote 3
              • Sallyfgdfh
                Sallyfgdfh last edited by

                Hello
                Many sites can help you solve your problem
                One of the best hack and security websites in Iran that also provides security services for outsiders is PentestCore whose web site addresses are as follows:
                https://pentestcore.com/

                1 Reply Last reply Reply Quote 0
                • 1 / 1
                • First post
                  Last post
                • I have a metadata issue. My site crawl is coming back with missing descriptions, but all of the pages look like site tags (i.e. /blog/?_sft_tag=call-routing)
                  Rajesh.Prajapati
                  Rajesh.Prajapati
                  0
                  2
                  43

                • Transferring Domain and redirecting old site to new site and Having Issues - Please help
                  kwoolf
                  kwoolf
                  0
                  4
                  330

                • Could Anyone Take a Look at Our Site?
                  seo--team-jlck
                  seo--team-jlck
                  0
                  4
                  135

                • Was my site hit by Panda or Penguin? Looking for diagnosis help
                  stever999
                  stever999
                  0
                  9
                  304

                • Please help on this penalized site!
                  Marcus_Miller
                  Marcus_Miller
                  0
                  14
                  295

                • Can someone please help me understand my sites recent loss of rankings?
                  benners
                  benners
                  0
                  3
                  274

                • It appears that Googlebot Mobile will look for mobile redirects from the desktop site, but still use the SEO from the desktop site.
                  BenRWoodard
                  BenRWoodard
                  0
                  3
                  414

                • Not ranking well after site was hacked
                  Chris-at-Magoosh
                  Chris-at-Magoosh
                  0
                  3
                  644

                Get started with Moz Pro!

                Unlock the power of advanced SEO tools and data-driven insights.

                Start my free trial
                Products
                • Moz Pro
                • Moz Local
                • Moz API
                • Moz Data
                • STAT
                • Product Updates
                Moz Solutions
                • SMB Solutions
                • Agency Solutions
                • Enterprise Solutions
                • Digital Marketers
                Free SEO Tools
                • Domain Authority Checker
                • Link Explorer
                • Keyword Explorer
                • Competitive Research
                • Brand Authority Checker
                • Local Citation Checker
                • MozBar Extension
                • MozCast
                Resources
                • Blog
                • SEO Learning Center
                • Help Hub
                • Beginner's Guide to SEO
                • How-to Guides
                • Moz Academy
                • API Docs
                About Moz
                • About
                • Team
                • Careers
                • Contact
                Why Moz
                • Case Studies
                • Testimonials
                Get Involved
                • Become an Affiliate
                • MozCon
                • Webinars
                • Practical Marketer Series
                • MozPod
                Connect with us

                Contact the Help team

                Join our newsletter
                Moz logo
                © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                • Accessibility
                • Terms of Use
                • Privacy