How to Check Whether a Website Has a Virus
A website infection is not always immediately visible. Sometimes a website appears to work normally while sending spam in the background, creating unwanted subpages, redirecting selected users, or allowing an attacker to regain access to the server.
The sooner you identify the problem, the greater the chance of limiting the damage, avoiding a hosting suspension, and protecting the website’s position on Google.
The most common signs of an infected website
1. The website redirects to ads or unfamiliar sites
After opening the website, a user is taken to an online shop, an advertising page, a fake contest, a gambling service, a page displaying a message about a supposed virus, or an unfamiliar domain.
The redirect may occur only on phones, on the first visit, after arriving from Google, for users who are not logged in, or in particular countries and at certain times of day. For this reason, the website administrator may not notice the infection themselves.
2. Google displays a security warning
Concerning messages include: This site may harm your computer, Deceptive site ahead, This site may have been hacked, or Security issues detected.
In this situation, check the security report in Google Search Console. Removing the warning alone does not solve the problem—the website must first be cleaned and the cause of the break-in removed.
3. Unfamiliar subpages have appeared in Google results
The website owner may notice Japanese or Chinese characters in Google, pages about medicines, loans, or casinos, hundreds of new URLs, unfamiliar titles and descriptions, or content that is not in the administrator panel.
This is often known as SEO spam. Malicious code generates subpages visible mainly to search-engine crawlers, so the website owner may not see them when browsing the site normally.
4. The hosting provider has blocked the website
The hosting provider may block a website or an entire account after detecting malicious files, mass email sending, excessive CPU load, attacks on other servers, or a phishing script.
Do not delete only the files identified by the hosting provider. They are often a symptom of an infection, not its original cause.
5. Unknown files appear on the server
Pay particular attention to:
- PHP files in directories intended for images
- files with random names
- new
index.php files
- modified
.htaccess files
- files containing incomprehensible, encoded code
- files that reappear after deletion
Not every unusual file is a virus. Do not delete it without analysis, because it may be part of a legitimate extension or website functionality.
6. An unknown administrator account has appeared
Check the user list in the CMS panel and directly in the database. Warning signs include administrator accounts you do not recognize, changed email addresses, new accounts created without your knowledge, administrators hidden from the panel’s standard view, and a change to the website owner’s password or email address.
It may be necessary to remove an unknown user, but that is not enough if the attacker has left an additional access mechanism on the server.
7. The website has become very slow
A sudden drop in performance may be caused by sending spam, mining cryptocurrency, running external scripts, generating thousands of subpages, or attacks launched from your server. Slow performance should be investigated, especially if CPU, memory, or bandwidth usage has also increased.
8. The website is sending unfamiliar messages
Check whether the server is sending spam, fake invoices, phishing messages, mass notifications to unknown recipients, or messages using your domain’s address. Sending spam can quickly result in the domain or server IP address being blocked.
9. The website’s content or appearance has changed
Signs of a break-in may include a changed homepage, unfamiliar ads, additional footer links, hidden links, new forms, foreign JavaScript code, or a message left by the attacker.
Check not only the current content but also template files, modules, widgets, and entries stored in the database.
How to check a website safely
Make a copy of the current state
Before starting the analysis, back up all files, the database, server configuration, and access and error logs. Even an infected backup may be needed to determine how the break-in happened and recover data deleted by mistake.
Check the website from another device
Open the website on a phone, in private-browsing mode, without logging in to the panel, through another internet connection, and after arriving from a search engine. Some infections hide from the administrator or run only under specific conditions.
Check files and modification dates
Check which files were modified most recently—especially those changed when no updates or website changes were being made. A modification date is only a clue, because an attacker may change it or infect an older file.
Check the database
An infection may be located in article content, website settings, widgets, the user table, automatically loaded options, or records responsible for scheduled tasks. Scanning files alone does not guarantee that the website is clean.
Check every website on the hosting account
If several websites are on one account, each one should be checked. An old, unused WordPress or Joomla installation may be the source of a reinfection affecting the other sites.
Is an online scanner enough?
An external scanner may detect visible redirects, suspicious JavaScript, a domain’s presence on a warning list, and some known malware signatures. However, it does not have access to the entire file system, database, cron jobs, or hosting accounts.
No warning from a scanner does not mean the website is safe.
When is professional help needed?
Professional analysis is especially recommended when:
- the website redirects users
- the hosting provider has blocked the account
- the virus returns after deletion
- several websites are on the server
- SEO spam has appeared on Google
- customer data may have been accessed
- you do not have a current, reliable backup
- you do not know which files are legitimate
Do not delete files at random or restore the website without first securing its current state. Incorrect actions may destroy evidence of the break-in, remove important data, or leave an active backdoor behind.