Skip to content
Ukraine

How to check a website for viruses: step-by-step guide

Authoradmin 7-08-2026, 19:17 227
How to check a website for viruses: step-by-step guide
Advertising

How to check a website for viruses: step-by-step guide

When a website starts behaving strangely, it is usually not noticed right away. Somewhere there is an extra redirect, somewhere the browser complains about dangerous content, and sometimes the problem only arises after a user complaint or a letter from the hosting provider. At such a moment, it is important not to panic and not to click on all the buttons in the admin panel. First, you need to understand what exactly to look for and how to check the website safely.

Checking a website for viruses is not just about running one online scanner. Sometimes it involves embedded malicious code in the template, sometimes it is a phishing page that someone has placed in the website's folder, and sometimes it is a hidden redirect that sends visitors to another resource only under certain conditions. It can also happen that the website is formally 'clean', but one of the theme files is infected, and that is enough for search engines to start raising alarms.

If you want to quickly get oriented in a related topic, it will also be useful a guide to checking a website for fraud. The logic partially overlaps: it is important to look not only at the technique but also at the reputation, behavior of the pages, and strange traces on the site.

What does it mean to 'check a site for viruses' and when is it necessary

The word 'viruses' in colloquial speech often refers to everything: malicious JavaScript, phishing pages, embedded iframes, link substitution, spam scripts, hidden redirects, and even unwanted pop-ups. In practice, it is useful to separate these things because the method of checking and removal will be different.

Phishing is when a site or its page pretends to be something else: a login form, a bank, an online store, a payment page. The goal is simple — to steal data. Malicious code is a broader concept. It can be a script that injects ads, loads an external file, steals sessions, or opens access for an attacker. A hidden redirect is a separate story: the visitor seems to open your site, but a second later finds themselves at a completely different address. And all of this may not be visible during a regular view of the homepage.

A quick website check for malware is needed if:

  • the browser or antivirus warns of danger;
  • Visitors complain about pop-ups, redirects, or strange requests;
  • The search engine marks the site as suspicious;
  • Unknown users or files have appeared in the admin panel;
  • The site started behaving differently after installing a plugin, theme, or update;
  • The logs show requests to files that you did not add.

And one more practical point: not all problems are related to the site itself. Sometimes the administrator's computer gets infected, and then the malicious code is brought back into the CMS via FTP or the control panel. Therefore, checking the site almost always goes hand in hand with checking the working devices.

Preparation before checking: what to save and where not to click

Before opening a suspicious site and running scanners, it's worth preparing minimal protection. This is not paranoia, but normal hygiene. You wouldn't reach into an electrical panel with bare hands — the same logic applies to the site, just the risk is different.

First, save important data. If you have access to hosting and the control panel, make a backup of files and databases. Even if the backup is old, it will help compare what exactly has changed. If there is no access, at least export the list of files and document the current state: modification date, size, suspicious names.

Next — be cautious when opening the site. Do not access it from your main work device if you have doubts. It is better to use a separate browser profile, updated antivirus, and, if possible, an isolated environment. Do not manually download anything from the site until you understand what the file is. Do not log in to the admin panel using public Wi‑Fi. And do not open attachments or archives that suddenly 'recommend' downloading after visiting.

If the site has already raised suspicions, it is not advisable to immediately clear the cache, delete 'everything unnecessary', and reinstall the CMS blindly. First, document the traces. It will be easier to understand where the problem came from later. Sometimes one strange file in the root provides more clues than three hours of chaotic cleaning.

Online website virus check: quick services and how to use them

An online website virus check is the fastest start when you need to determine if there are any obvious signs of infection. Such services usually do not require access to hosting: you enter the website address, and the scanner checks the page, external resources, suspicious redirects, blacklists, and sometimes part of related files.

Conditionally, such services can be divided into several types. Some look for signatures of malicious code in HTML and JavaScript. Others check the domain's reputation and presence on block lists. Others investigate the behavior of the page: whether it redirects to another address, whether it loads dangerous content, or whether it disguises itself as a phishing form. There are also combined solutions that perform several checks at once.

Working with them is easy, but interpreting the results needs to be done carefully. One alarming flag does not always mean infection. For example, an external script may be a legitimate analytics counter, an ad block, or a widget. However, if a service shows a suspicious redirect and another shows an unknown iframe in the page code, that is already a reason to dig deeper.

It is useful to run not just one, but several independent checks. This makes it easier to distinguish a real problem from a false positive. And be sure to look at what exactly the service found: the page URL, a specific code fragment, a mention of the domain in blacklists, a suspicious chain of transitions. The general message 'threat detected' does not explain anything by itself.

If you also want to understand the technical side of protection, it is worth looking at how to check the SSL certificate of the site. Often, security issues coexist: somewhere the certificate is broken, somewhere the traffic is not following the right scenario, and the user ultimately sees a warning and leaves.

Manual website check for malicious code: signs of infection

Automated services are useful, but manual checks are often more accurate. Especially if the infection is hidden deep in the template or inserted in a way that it only triggers on a specific page. First, check the HTML pages and templates, then the included scripts, and finally the chain of loading external resources.

What signs should raise concern:

  • unknown

    script

    -blocks and links to third-party domains;
  • iframe that does not relate to your site and is not explained by the page's purpose;
  • redirects via JavaScript, meta refresh, or server headers;
  • code obfuscated with long strings without clear logic;
  • hidden forms, fields, and elements with display none;
  • unexpected links in the footer, sidebar, comments, or ad blocks;
  • suspicious calls to eval, document.write, and similar mechanisms;
  • files with names like cache.php, temp.php, update.php in unexpected places.

If the site template has not been updated for a long time, and suddenly a new script block appears, it is almost always a reason to stop and check the source. Sometimes an attacker disguises the insertion as 'service code' or even adds comments to make the file look ordinary. And yes, evil jokes like 'well, this is probably from the theme' usually end up wasting time.

Check redirects separately. They can be not only in the page code but also in .htaccess, in server configuration, in plugins, or in JS files. A user opens the homepage, and a second later they land on another site — and sometimes the reason has to be sought not on the page but in the routing rules.

Step-by-step check of files, CMS, and database

If a systematic approach is needed, check the site layer by layer. This way, it's easier not to miss the source of infection and not to delete unnecessary items.

  1. Compare the current files with a backup or a 'clean' version of the CMS. Look for new files, changed dates, unusual sizes, and strange names.

  2. Check the CMS core. If system files have been changed, that's a warning sign. Normally, updates should be transparent and explainable.

  3. Inspect plugins and themes. This is where malicious code is often embedded after a hack because these folders change most frequently and are less noticeable.

  4. Look for suspicious inserts in configuration files. Sometimes the infection resides in places that are rarely opened manually.

  5. Check the database for foreign links, hidden HTML inserts, new admin accounts, and strange values in the settings fields.

  6. Compare the content of the pages before and after the infection if you have archives. Pay special attention to text blocks, the footer, and fields that are output automatically.

Sometimes not only content is hidden in the database, but also code for loading external scripts. Therefore, if everything looks normal in the files but suspicious behavior persists, the cause may lie there. This is one of those cases where the mechanical 'I deleted the file, why didn't it help?' does not work.

Another important point is checking users and access rights. After a hack, new administrators often remain, and old accounts gain elevated privileges for no apparent reason. Check the list of accounts, recent logins, password changes, and actions in the admin panel.

How to check a website using webmaster tools and antivirus scanners

Once the basic manual check has been conducted, it is useful to connect tools that see the site from the outside. They do not replace internal diagnostics but complement it well. Here, webmaster panels, server logs, antivirus scanners, and domain reputation services are particularly important.

Webmaster panels show warnings about malicious pages, indexing issues, phishing, and suspicious redirects. This is one of the first signals if the site has already come to the attention of search engines. In server logs, you can see unexpected requests to files, frequent authorization errors, suspicious POST requests, and activity during off-hours. Sometimes the log becomes the starting point: everything seems calm, and then you see a whole stream of requests to an unknown script.

Antivirus scanners on the server are useful if you have access to the file system. They look for signatures of malicious code, suspicious archives, shells, and files with atypical behavior. However, a sensible approach is also needed: a scanner may miss a new modification or, conversely, flag a legitimate file as dangerous. Therefore, it is better to compare the results with a manual check.

Domain reputation services help understand how a site is perceived externally. If a domain suddenly ends up on blacklists, it is no longer just an internal failure. This means the problem is noticeable beyond your server. For a deeper assessment, it is useful to cross-check the results from several sources and not rely on a single warning.

If you want to expand the toolset, also pay attention to checking the site for hidden subscriptions. Sometimes unwanted schemes disguise themselves as regular services, and then the infection does not appear as a 'virus' but as a chain of imposed actions.

What to do if viruses or malware are found

The main rule is not to keep the site running if you are not sure that the problem is localized. First, isolate it from visitors if possible. Sometimes it is enough to temporarily close access to the infected sections or enable maintenance mode.

Next, delete the infected files or replace them with clean versions from a backup. If the malware is embedded in a theme, plugin, or core, it is better to reinstall the component from an official source rather than cleaning it manually piece by piece. When the infection has affected the database, you will need to remove suspicious inserts, check users, and review the content of all automatic fields.

After cleaning, be sure to change passwords: for the admin panel, FTP/SFTP, hosting, database, email, and related services. If a password was repeated somewhere, change it there as well. Otherwise, an old loophole will quickly become a new one.

Then update the CMS, plugins, themes, and server software, if accessible. Many infections exploit old vulnerabilities, and as long as they are not closed, re-infection is just a matter of time. After that, conduct a re-check of the site for viruses, preferably using several methods at once.

And also: do not forget about monitoring after recovery. The first few days are especially important. Check logs, indexing, page content, and form behavior. Sometimes malicious code leaves a 'backup' or hidden path that activates later.

How to protect the site from re-infection

The best treatment for a site is not a heroic cleanup after a hack, but proper prevention. It's less exciting, but much cheaper in terms of time and nerves.

  • update CMS, plugins, and themes without delays;
  • remove unused extensions and old templates;
  • restrict access rights to files and directories;
  • do not store the same passwords for different services;
  • enable two-factor authentication where possible;
  • make regular backups and check that they can be restored;
  • monitor the logs and warnings from the hosting;
  • periodically run an online virus check on the site and manually inspect key files.

It is also worth checking the computers from which you manage the site. If the infection comes through an FTP client or browser session, a clean server alone will not save you. It is also useful to periodically review the access list: who has access to the admin panel, who knows the backup codes, who can change the DNS. Sometimes the problem is not in the code, but in overly broad permissions.

If approached systematically, checking the site for viruses stops being an emergency ritual and becomes a regular part of maintenance. And this is perhaps the best outcome: not to extinguish a fire, but to prevent it from flaring up.

How useful is the material?Evaluation helps us choose topics
00 ratings
Analytics

Story statistics

227views
0comments
11min read
58 / 662rank among section stories

Among the top 10% most-read stories in this section.

Discussion

No one has spoken yet — be the first.

Comments are written by participants Log in to the site — it's free and takes a minute. Comments are moderated.
Log in
Advertising

What searches this page answers