When a hosting account has been used for malware, spam or phishing, you have three ways back: restore a clean backup, reset the account and rebuild, or clean the existing site in place. Each one has a cost, and the wrong backup can bring the infection straight back. This page compares the three and explains the backup habits that make recovery quick.
Containment, finding the way in, passwords, reporting to CERT-In and prevention are covered step by step in what to do if your website has been hacked or defaced. This page focuses on choosing between a reset, a restore and a clean-up.
If you have a backup from before the attack, restoring it is usually the fastest route; on Domain India cPanel and DirectAdmin hosting, JetBackup 5 keeps the last 5 weekly backups. If no clean backup exists, either reset the account and rebuild from checked content, or clean the site in place. Whatever you choose, never re-upload files you have not checked: an infected backup brings the malware back, and repeated abuse can lead to suspension under our Acceptable Use Policy.
1. Reset, restore or clean: which fits?
| Option | What it means | Good when | The risk |
|---|---|---|---|
| Restore a clean backup | Put files and databases back to a date before the attack | You have a backup you trust | Anything added after that date is lost |
| Reset and rebuild | Empty the account, install fresh software, import only checked content | No clean backup, and the site is small | More work, and everything not re-imported is gone |
| Clean in place | Find and remove every malicious file, user and database entry | No clean backup and a large site | Easy to miss one hidden back door |
Whichever you choose, change every password and fix the way the attacker got in, usually an outdated plugin or a stolen password, or the site is soon hacked again.
2. Restoring a backup safely
Choose the right date. The backup must come from before the first sign of trouble, ideally before the date of the first malicious file you found. A backup from yesterday may already contain the malware.
Use the backups in your panel. On Domain India cPanel and DirectAdmin hosting, JetBackup 5 takes a backup of your account every Sunday and keeps the last 5 copies, so you can go back about five weeks. You can restore only the part you need, such as your files or one database. See backup and restore with JetBackup. On Webuzo hosting, Domain India backs up your account every night; to restore, open a support ticket saying what to restore and from which date. See restoring a Webuzo backup.
Using your own local backup. Scan it on your computer before you upload anything, compare it with a fresh download of your CMS, and look for PHP files in upload folders or files you do not recognise.
Restoring files or a database replaces the current copy. If you need orders, posts or sign-ups added since the backup date, export them first and copy them back by hand once the site is clean.
3. Resetting the account and rebuilding
A reset means starting with an empty account: no old files, no old databases, nothing the attacker could have hidden. It is the most thorough option and the most work.
- Download a copy of everything first.Files, databases and any mail you need. This copy is infected, so keep it only as a record and as a source of content, never as something to upload back in one go.
- Empty the account.Delete the site files and the old databases in your control panel's File Manager and database tools, and remove FTP accounts, cron jobs and email forwarders you did not create. If you would rather have the whole account reset, ask support in a ticket what is possible for your plan.
- Install fresh software.Install a new copy of your CMS, for example WordPress through Softaculous, and only current versions of the plugins and themes you really need, from their official sources.
- Import only checked content.Bring back text, images and a checked database export, not PHP files from the old site.
- Set new passwords and turn on two-factor authenticationfor the CMS, the control panel and your client area.
4. Cleaning in place
Cleaning keeps your existing site, but every file, user, cron job and database table has to be checked, and one missed back door lets the attacker straight back in. Follow the checklist in the hacked-site guide, and for Google warnings the Google warning cleanup guide.
On our cPanel servers, Imunify360 scans files and removes known malicious code from infected files automatically, keeping the original for 14 days (measured 20 September 2026). You cannot start that scan yourself and you are not emailed when it finds something, so ask support in a ticket what it found for your account. It catches known malware; it cannot fix an outdated plugin or a stolen password.
5. Why re-uploading infected files is serious
Domain India's Acceptable Use Policy prohibits hosting malware, viruses or phishing pages on any service. It treats phishing and malware as severe violations that can lead to termination without refund, and repeated violations can lead to suspension without notice. A suspended account can ask for a review by contacting support with a remediation plan.
6. Backup habits that make recovery easy
- Keep your own copies off the server. Download a backup regularly, especially before updates, and store it on your computer or cloud storage. See how to download a backup of your site.
- Back up more often if the site changes daily. The panel's backup is weekly, so a shop taking daily orders should keep extra database copies.
- Keep everything updated and remove unused plugins and themes. Read why and how WordPress sites get hacked.
Frequently asked questions
Should I restore a backup or clean my hacked website?
Restore if you have a backup from before the attack started, because it is usually faster. Then update everything and change passwords, because the backup has the same weakness the attacker used. If you have no clean backup, reset and rebuild from checked content, or clean the site in place.
Can I upload my old backup after a hack?
Only after you have checked it. A backup taken after the infection started contains the malware and brings it straight back. Scan it, compare it with fresh CMS files and look for unknown PHP files before uploading.
Will Domain India clean my hacked website?
Imunify360 on our cPanel servers removes known malicious code automatically, but cleaning your site files, plugins and database is your responsibility or your developer's. Open a ticket to ask what the scanner found for your account.
Can my account be suspended for malware?
Yes. Domain India's Acceptable Use Policy prohibits hosting malware or phishing pages. Repeated violations can lead to suspension without notice, and severe violations to termination.
Ready to recover? Restore from JetBackup if you have a clean date, follow the hacked-site checklist for the rest, and open a support ticket if your account is suspended or you need to know what the scanner found.
Tell us your domain, what you saw and when it started, and what you have already changed.
Open a support ticket