Why Does a Virus Return After Malware Removal?
The Site Was Cleaned — and It Is Infected Again. Why?
This is one of the most common scenarios we encounter: a site owner manually removes virus-infected files, the site works correctly for a few days, and then the same thing happens again. The infection returns — sometimes sooner than before.
This is not bad luck or an especially aggressive hacker. It is the result of incomplete cleanup. Below, we explain the five main reasons why a virus returns.
Reason 1 — The Backdoor Is Still on the Server
A backdoor is a file or piece of code that hackers install alongside the main virus. Its sole purpose is to enable a return — even if the site owner removes everything else.
Backdoors are deliberately hidden in inconspicuous places:
- In cache directories (
/wp-content/cache/)
- In PHP session files (
/tmp/sess_*)
- In uploaded-file directories (
/wp-content/uploads/) as .php files
- Injected into legitimate WordPress files beneath the original function
Signature-based antivirus scanners often fail to detect them because they are obfuscated or use non-standard encoding techniques.
Reason 2 — The Vulnerability That Let the Attack In Still Exists
Removing malicious code does not remove the cause of the infection. If the attack happened through:
- An outdated plugin with a publicly known vulnerability — and that plugin is still on the same version
- A weak FTP or admin password — and the password has not been changed
- An exploit in a premium theme — and the theme has not been updated
...then a bot will find the same vulnerability and return. Automated attack scanners constantly search the internet and may find the same site again within hours.
Reason 3 — An Infected Backup
If you restored the site from a backup after cleaning it, and the backup was made after the infection occurred (or even worse — an automatic backup overwrote the clean version with an infected one), the virus returned with it.
Always check the backup date and compare it with the date the infection was first observed. A backup from before the attack is safe; a backup made during an active infection carries malware.
Reason 4 — An Infected Database
Many site owners focus on files and overlook the database. Yet malicious code can live in the wp_options, wp_posts, or wp_usermeta tables. Every time the site loads, PHP reads this data and executes the code it contains.
Symptom: the site looks clean over FTP, but still redirects or displays spam. The cause is an infection in the database, which file cleanup does not touch.
Reason 5 — No Hardening After Cleanup
Even if all traces of the infection have been removed and the software updated, without hardening the site is only a slightly more difficult target — not truly secured.
Hardening is a set of measures that actively makes another attack more difficult:
- Blocking access to
xmlrpc.php and wp-json if they are not used
- Restricting file permissions (chmod 644/755)
- Enabling 2FA on the admin account
- Configuring HTTP security headers
- File integrity monitoring with alerts
Without these steps, another bot will find the site and try again — it is only a matter of time.
What Can You Do to Stop the Virus from Returning?
Effective site cleanup is a two-step process:
- Deep cleanup — removing not only the symptoms, but also all backdoors and malicious code from the database
- Hardening — closing the vulnerability the attack came through and actively protecting against another one
If the virus returned after your site was cleaned, contact us and learn about our professional website malware removal service. Diagnosis is free, and our comprehensive cleanup with hardening comes with a 30-day malware-return guarantee. After cleanup, we also implement post-breach website security to close the way to another infection.