Guide

What is malware?

Malware is any software written to do something to a computer that its owner did not agree to. On a website or a server, that usually means stealing traffic, stealing data, or quietly borrowing your machine for someone else's purposes.

The word covers a lot of ground. A keylogger on a laptop and a hidden redirect on a WordPress site are both malware, but they behave nothing alike. This guide is about the kind that lands on websites and servers — what it does, how it gets in, and what it actually takes to get rid of it.

The types that matter for websites and servers

Most infections we deal with fall into a handful of families. It is common to find several at once, because whoever got in first often sells that access on.

  • Webshells. A small script uploaded into your site's files that gives an attacker a control panel in the browser. They can browse your filesystem, run commands and upload more tools. Often disguised with an innocuous filename and dropped into an uploads or cache folder.
  • Backdoors. Anything that restores access after you think you have cleaned up. A rogue admin account, an extra SSH key, a modified core file, a scheduled job that re-downloads the payload. This is why infections come back.
  • SEO spam. Hidden pages and links injected into your site to promote someone else's products — often pharmaceuticals, counterfeits or casinos. Frequently cloaked, so it renders for search engines and not for you.
  • Redirect malware. Code that sends some of your visitors somewhere else. Usually conditional: mobile visitors only, or first-time visitors only, or visitors arriving from a search engine. That selectivity is what makes it hard to reproduce.
  • Credit card skimmers. Injected JavaScript on checkout pages that copies card details as they are typed. Small, quiet and expensive.
  • Cryptominers. Software that uses your server's CPU to mine cryptocurrency. The symptom is a slow, hot, expensive server rather than anything visibly wrong with the site.
  • Ransomware. Encrypts files and demands payment. Less common on web servers than on office networks, but devastating when it lands.

How infections usually start

Almost none of this is personal. Attacks on small and medium websites are automated: software scans enormous numbers of servers looking for one specific weakness, and takes whatever it finds. The common entry points are unglamorous.

  1. An out-of-date plugin, theme or CMS. When a vulnerability is published, scanning for it starts almost immediately. Sites that have not updated are found in bulk.
  2. Reused or weak credentials. Admin passwords that appeared in an unrelated data breach get tried against your login form.
  3. An insecure upload path. A form that accepts files without checking what they are, in a directory where the server will happily execute them.
  4. A neighbouring site on the same server. If several sites share a machine and permissions are loose, compromising the weakest one can be enough to reach the rest.

The part people underestimate

By the time you notice symptoms, the original hole is rarely the only problem. An attacker who has had access for a while will have planted several ways back in. Deleting the files you can see, without finding those, is why so many sites get reinfected within days.

Signs you might be infected

Malware on a website is designed not to be obvious to you, the owner. The clues are usually indirect:

  • A browser or search warning appears when visiting your own site
  • Pages you never created show up in Google results for your domain
  • Visitors report redirects you cannot reproduce yourself
  • The server is unusually slow, or CPU use has jumped with no change in traffic
  • Files have modification dates you cannot account for
  • Admin users exist that nobody on your team created
  • Your host emails about abuse, spam being sent, or resource limits

We go through these in more detail in signs your website has been hacked.

Think something is already wrong? We can look today.

What proper malware removal involves

Running a scanner and deleting whatever it flags is not removal — it is tidying. A cleanup that holds has to answer the question the scanner cannot: how did they get in, and what else did they leave?

  1. Investigate before deleting. Work out the entry point and the timeline. Keep evidence rather than destroying it, because it tells you what else to look for.
  2. Quarantine, don't just delete. Isolating malicious files preserves what happened while stopping it running.
  3. Hunt the persistence. Rogue admin accounts, injected core files, overwritten configuration, cron and systemd jobs, fake system binaries, extra SSH keys.
  4. Restore what was damaged. Repair core files and configuration rather than leaving a site half working.
  5. Harden the way back in. Block script execution in upload directories, lock down the firewall and SSH, audit administrator accounts, and fix whatever let them in.
  6. Verify and keep watching. Confirm every site is clean and online, then monitor — because reinfection attempts follow a successful compromise.

Removal on one site versus a whole server

If you host several sites on one VPS or shared server, cleaning a single site is often not enough. Malware that reached the filesystem may have touched neighbouring sites too, and one missed backdoor puts everything back at risk. That is why we treat the server as the unit of protection rather than the individual site — see VPS server security for how that spreading works.

Related guides

Unlimited malware removal, for one monthly price.

We clean websites and VPS servers as often as it happens, monitor them 24/7, and harden them so it doesn't happen again.

Book a demo