- Discovering malware on your website is stressful, but a calm, methodical process fixes it faster than panic ever does.
- Here is exactly what to do, step by step.
Malware on a hosted website usually shows up as strange redirects, unexpected pop-ups, a Google "This site may be hacked" warning, or a direct notification from your hosting provider. The response process is the same regardless of how it was discovered.
Step 1: Confirm and Contain
- Change all passwords immediately — hosting account, cPanel, CMS admin, database, FTP.
- Take the site offline temporarily (maintenance mode) if it is actively serving malicious content to visitors.
- Contact your hosting provider — some offer malware scanning and removal as part of their support or a paid add-on.
Step 2: Identify the Scope
- Scan all files for recently modified timestamps around the suspected infection window.
- Use a malware scanning plugin (for WordPress) or a server-level scanner if your host provides one.
- Check for unfamiliar admin users or unexpected scheduled tasks that may have been added.
Common Malware Types Found on Nepali Hosted Sites
- SEO spam injection: hidden links or pages promoting unrelated products (often pharmaceuticals or counterfeit goods) inserted into an otherwise legitimate site to exploit its search ranking — frequently the first sign is a strange page appearing in Google search results that does not exist anywhere in the visible site menu.
- Malicious redirects: visitors from search results get silently redirected to an unrelated site, while direct visits appear normal — a pattern designed specifically to delay discovery by the site owner.
- Backdoor scripts: a small, disguised file (often named to look like a legitimate core file) that lets an attacker back in even after a password reset, which is exactly why a full file scan matters more than just changing credentials.
- Outdated-plugin exploits: by far the most common entry point on WordPress sites in Nepal, where an unpatched, months-old plugin version provides a known, published vulnerability an automated attack script can exploit without any targeted effort.
Step 3: Clean the Infection
- Restore from a clean backup taken before the infection date, if one exists — often the fastest, most reliable fix.
- If no clean backup exists, manually remove malicious code identified by scans, or reinstall core CMS files fresh while preserving only verified-clean content.
- Update every plugin, theme and CMS core to current versions — outdated software is the most common infection vector.
Step 4: Verify and Request Delisting
- Rescan thoroughly to confirm the infection is fully removed before bringing the site back online.
- If Google flagged the site, use Google Search Console to request a malware review after cleanup.
- Monitor closely for several weeks after cleanup for any signs of reinfection.
When to Call a Professional vs DIY
A confident WordPress user comfortable with FTP and phpMyAdmin can often handle a straightforward, single-plugin-exploit infection with a security plugin's scan-and-clean tools. A backdoor-based infection, a compromise where the scope is unclear, or any site handling payment or significant customer data is worth escalating to a professional cleanup service or your host's security team — the cost of a proper cleanup is small next to the cost of an incomplete one that leaves a hidden backdoor and reinfects weeks later, undoing the DIY effort entirely.
Preventing Reinfection
- Keep every plugin, theme and CMS core updated promptly.
- Remove unused plugins and themes entirely rather than leaving them deactivated.
- Enforce strong, unique passwords and enable two-factor authentication on admin accounts.
- Install a reputable security plugin with active malware scanning.
Frequently Asked Questions
Can my hosting provider clean the malware for me?
Many providers offer this as part of managed hosting or as a paid service — worth asking directly rather than attempting complex cleanup alone if uncertain.
How did the malware get in if I have a password?
Most infections come through outdated, vulnerable plugins or themes rather than password compromise — updating everything promptly is the single highest-impact prevention step.
Will a malware infection show up in my hosting account's resource usage?
Often, yes — SEO spam injections and redirect scripts frequently cause unusual CPU or bandwidth spikes, which is one reason unexpected resource-usage alerts are worth investigating rather than dismissing as normal growth.
Is it safe to just delete the whole site and start fresh instead of cleaning it?
It removes the immediate infection but risks losing legitimate content and does not guarantee the original entry point (a vulnerable plugin, weak credentials) is fixed on the rebuilt site — a proper scoped cleanup plus hardening is usually the more reliable long-term fix.
Need help cleaning an infected website? Contact our support team or get help now.