Finding out your site has been hacked is stressful, and stress leads to hasty decisions — deleting the wrong thing, or tipping the attacker off before you understand what they did. A calm, ordered response makes the cleanup faster and the outcome better.
Do not panic-delete
Your instinct is to remove the first suspicious file you find. Resist it. Until you understand how the attacker got in and what they touched, deleting one symptom often just hides the evidence you need — and leaves the entry point wide open.
Take a snapshot first
Before changing anything, capture the current state — a full backup of files and database, even in its infected form. It is the record of what happened, and you may need it to understand the scope of the compromise.
Change the important passwords
Reset admin passwords, hosting and control-panel logins, database credentials, and any connected accounts. If an attacker has valid credentials, no amount of file cleanup keeps them out.
Take stock, do not guess
Look for the signs that tell you the scope: unknown users, modified files, unexpected scheduled tasks, redirects. The goal at this stage is understanding, not fixing — you cannot clean what you have not mapped.
Then clean it properly
Real recovery means removing the malicious code and files, closing the vulnerability that let them in, and hardening the site so the same route does not work twice. Cleaning the infection without closing the door is the single most common reason sites get reinfected.
If any of this is beyond where you are comfortable, that is exactly the point to bring in help — before a bad day becomes a worse one.