← Kornet Labs

Your Host Suspended Your Site for Malware: How to Get Back Online

The email usually arrives with a subject like "Account suspension notice" and a paragraph of policy language. Your site is offline, your inbox is filling with "is your site down?" messages, and the clock is running. Here is the path back, step by step.

First: why hosts do this

A suspension feels like punishment, but from the host's side it's containment. An infected site on shared hosting can spam from the server's mail system, attack other websites, and get the server's shared IP address blacklisted, hurting every other customer on the machine. Suspending the account stops the bleeding. The good news buried in that: hosts don't want your site offline either, and every host has a routine process for reinstating cleaned sites. Your job is to move through that process quickly and only once.

Step 1: Read the notice like a lawyer

The suspension email usually contains more useful information than it seems to. Look for:

  • What they found. Many hosts include a list of infected file paths from their own scanner, or attach a scan report. This list is gold for the cleanup, but treat it as a starting point, not an inventory: host scanners flag what they can see, and persistence mechanisms (backdoors, fake plugins) are exactly what they tend to miss.
  • What they require for reinstatement. Some hosts want a reply describing what you cleaned; some rescan themselves; some require you to request a review explicitly. Knowing the exit condition up front saves days.
  • What access you still have. In most suspensions, only web serving is switched off. FTP/SFTP and the control panel usually keep working, and that's your way in.

Step 2: Ask your host three questions

Reply to the suspension notice (or open a chat) and ask, in whatever words fit:

  1. Can you share the full list of files your scanner flagged, and the scan report?
  2. Is FTP/SFTP access still active during the suspension? (If not, ask for it to be enabled for cleanup.)
  3. What exactly do you need from me to reinstate the site, and do you rescan before reinstating?

Hosts handle hacked sites every day. A calm, specific message signals that this account is going to be an easy resolution, and support teams prioritize easy resolutions.

Step 3: Back everything up before you change anything

Over FTP or the control panel's file manager, download a complete copy of the site and export the database. Yes, the copy is infected; that's fine. It preserves your content, protects you if a cleanup step goes wrong, and some hosts' "cleanup" option is deleting the account's files, after which a backup is the only thing standing between you and starting from zero.

Step 4: Actually remove the malware

With file access, you have three routes, in increasing order of reliability:

  • Delete only what the host flagged. Fast, and sometimes enough to get reinstated, but the reinfection rate is high: the host's list rarely includes the backdoor that placed the flagged files. If the site gets suspended twice, the second conversation with the host is much harder.
  • Restore a known-clean backup. Genuinely effective if you have a backup from before the infection, know when the infection happened, and immediately fix the vulnerability that was exploited, or the same attacker walks back in through the same door, often within days.
  • Run a full scan and cleanup of every file and the database. The thorough option, and the one that makes the reinstatement stick. If your host has re-enabled web access for cleanup, or reinstates first and rescans after, this is the moment to run Kornet's free scan: it checks every file and the database, removes what doesn't belong, and produces a report you can forward to your host as evidence of the cleanup. One honest limitation: our scanner needs the site to be reachable to work, so on a hard-suspended site, ask the host to restore access for cleanup first; most will.

Step 5: Request reinstatement, with evidence

When you reply to the host, make their decision easy: say what was infected, what you removed or replaced, and what you changed to prevent recurrence (updates, password resets, removed software). If you have a cleanup report, attach it. Then ask them to rescan and reinstate. Most hosts turn this around within hours to a couple of days.

Step 6: Close the door behind you

Reinstatement without prevention is a subscription to this whole experience. Before you consider it done:

  1. Update everything: WordPress core, every plugin, every theme, and PHP if your host offers a newer version.
  2. Delete what you don't use: deactivated plugins and old themes are attack surface with zero benefit.
  3. Rotate every credential: WordPress admins, hosting panel, FTP/SFTP, database.
  4. Audit your admin users and remove any you can't account for.
  5. Remove nulled software. If any plugin or theme came from a "free premium downloads" site, delete it and buy or replace it. Pirated plugins are one of the most common infection vectors we see in real cleanups.
  6. Watch the site for two weeks. If symptoms return, there's surviving persistence, and the next step is a deeper sweep, not another spot-clean.

Written by the Kornet team, based on suspension cases we've worked through with site owners and their hosts.

Need a cleanup your host will accept?

Kornet scans every file and your database for free, and gives you a full report. You only pay $70 if we find malware.

Start the free scan
WordPress · files + database · one-time, no subscription