Knowledge Base

What do I do when MalwareGone detects malware on my site?

Overview

By the end of this article, you will know how to respond safely to a MalwareGone malware detection and get your website back to a clean, working state. The article first defines malware and explains how it usually reaches a website. It then tells you to change your File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), and shell access passwords immediately, because reused or stolen credentials are a common entry point. Two recovery paths follow: one for a site built on a Content Management System (CMS) such as WordPress, Joomla, Drupal, or Magento, and one for a custom application developed in house. A verification section, common issues, and prevention tips close the article.

What is malware?

Malware is short for malicious software. It is code installed on a website or application to perform an action the site owner did not intend, such as stealing data, redirecting visitors, sending spam, or hosting further attacks. A malware report identifies that unwanted code is present, but it does not tell you what the code did. Determining the exact behaviour and impact requires a full analysis of the code by your hosting provider or a security specialist.

Malware usually reaches a website through known vulnerabilities, unpatched or outdated software, weak or stolen credentials, or a newly discovered flaw that has no fix yet.

Change your passwords first

Change your passwords now, before you begin any recovery work. This applies to every website, no matter which software the site runs. Change the passwords for File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), shell access, the hosting control panel, and any administrator account on the website. Use a unique, strong password for each account. If credentials were stolen, cleaning the website without changing passwords allows the attacker to reinfect it.

Recover a site built on a Content Management System

Use this path if your website runs on a Content Management System (CMS) such as WordPress, Joomla, or Drupal, or on a store platform such as Magento. Complete these steps in order:

  1. Restore a backup taken before the date the malware was reported. This brings the website back online while you complete the remaining steps.
  2. Update the core CMS software to the latest version available from the vendor.
  3. Update every plugin, theme, module, and library installed on the website to its latest version.
  4. Remove any plugin, theme, or extension you no longer use, because unused components are still a possible entry point.
  5. Repeat steps 1 to 4 for every other website hosted on the same account, as malware often spreads between sites that share a server or account.

Recover a custom application developed in house

Use this path if your website runs on an application built for you rather than on a Content Management System (CMS). Do not delete, edit, or restore any files yet. Contact your hosting support team or the developer responsible for the application first, and let them investigate.

The people handling the case need to review the source and timestamp of the affected files, the server access logs, and related system records. Changing files before that review removes the evidence needed to find the root cause and slows the investigation. Once the vulnerability in the application is identified, ask the developer to fix it so the same route cannot be used again. This type of analysis usually takes several days. After the application is clean and the fix is in place, take a fresh backup of the website.

How to confirm your site is clean

Run a new MalwareGone scan after you finish the recovery steps. A scan that reports no malware confirms the website is clean. If the scan still reports malware, the infected files were not fully removed or the original vulnerability is still open. Return to the recovery path that applies to your website, and contact your hosting support team if the result does not change.

Common issues

Issue: The scan still reports malware after a backup restore.
Cause: The backup used was taken after the site was already infected, or the original vulnerability is still present.
Solution: Restore an earlier backup and confirm that all software, plugins, and themes are updated to the latest version.

Issue: Malware returns a few days after the site was cleaned.
Cause: Passwords were not changed, or another website on the same hosting account is still infected.
Solution: Change all File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), shell, and administrator passwords, and clean every website on the account.

Tips and best practices

  • Schedule automatic backups and keep several previous versions, so a clean restore point is always available.
  • Apply core, plugin, and theme updates as soon as they are released.
  • Use a separate hosting account for each website where possible, to limit how far an infection can spread.
  • Limit administrator accounts to the people who need them, and remove accounts that are no longer in use.

Similar questions

  • MalwareGone found malware on my website, what should I do?
  • How do I remove malware from my WordPress site?
  • How do I clean a hacked website after a malware report?
  • What are the steps to recover a website after malware is detected?
  • Why does malware keep coming back on my website?

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today