What Should a Website Malware Removal Report Include?
A Malware Removal Report — Why Does It Matter?
When the work is done, the specialist tells you, "everything is ready, the site is clean." But how can you check? How do you know you paid for actual work and not just for someone to press a button in a free scanner?
A malware removal report is not a formality — it is your only proof of the scope and quality of the service performed. Without a report, you cannot verify the work, you cannot make a warranty claim, and you do not know what was changed on your server.
What Should a Good Report Include?
1. Description of the Threats Found
The report should list exactly what was found:
- Type of malware (web shell, redirector, spam mailer, cryptominer, card skimmer)
- Locations of infected files (paths, names)
- Scope of the database infection (which tables were affected)
- Whether backdoors were found — how many and where
2. Attack Vectors — How the Hacker Got In
A good forensic analysis identifies where the attack came from:
- An outdated plugin or theme with a publicly known CVE vulnerability
- A password cracked through brute force
- A vulnerability in a contact form or uploader
- A compromised FTP account (password leak)
Without knowing the attack vector, you cannot close it. If the report does not include this information, ask directly.
3. List of Actions Performed
The report should document what was done:
- Which files were deleted or modified
- Whether the database was cleaned and which tables were affected
- Whether original CMS files were restored from the repository
- Whether passwords (which ones) and keys were changed
- Which updates were carried out
4. Hardening — What Was Secured
A thorough report also documents preventive measures:
- Changes to the .htaccess configuration
- File permissions that were set
- Security headers that were implemented
- Monitoring or alerts that were configured
- 2FA that was enabled
5. Recommendations for the Future
A good specialist does not just fix the problem — they educate. The report should include recommendations tailored to your site:
- Which plugins are worth replacing with safer alternatives
- How to configure backups to stay safe in the future
- Whether the site is suitable for ongoing monitoring
- Dates for the next updates
6. Confirmation That a Request Was Submitted to Google (If Applicable)
If the site was blocked by Google Safe Browsing, the report should include confirmation that a review request was submitted in Search Console, the submission date, and the expected response time.
A Report That Should Raise Suspicions
Be wary of reports that:
- Contain only screenshots from a scanner, with no description of what was found
- Are vague (e.g. "files scanned and malicious code removed") and contain no details
- Do not include information about what caused the attack
- Do not list any files or paths
How We Report
Every WebRatunek malware removal job ends with a written report containing the threats found, attack vectors, a list of all files changed, the scope of hardening, and recommendations. The report is the basis for the 30-day guarantee — without a report, there is no guarantee.
Need a full analysis and a report after cleanup? See our website malware removal service. If Google flagged your site, also see our help with a Google Safe Browsing block.