Skip to main content

Website protection

Malware Scanning

A malware scan is one source of evidence. It can find known patterns and suspicious changes, but a clean result is not proof that a website or account is uncompromised.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

Website malware may inject spam, redirects, credential stealers or administrator access. Some changes are visible in public pages, while others live in server files, databases, scheduled tasks or compromised accounts.

Different scanners see different layers. An external scanner observes public responses; a server-side scanner can inspect more files but still depends on access, signatures, heuristics and trustworthy operation.

Know the exposure

Common risks

01

False reassurance

Obfuscated, new, dormant or database-resident code may evade a limited scan.

02

Destructive auto-cleaning

Automatic deletion can break legitimate code, remove evidence or leave the original access route open.

03

Compromised scanner context

A tool running inside the affected account may be disabled, misled or unable to inspect other layers.

Investigate, do not ignore

Warning signs

  • Scanner results change without a corresponding update or investigation
  • Files reappear after deletion or reinfection follows a reported clean-up
  • Search spam or redirects affect only some devices, referrers or user agents
  • Unknown scheduled tasks, administrators, database entries or outbound connections remain
  • The scan reports clean while hosting, browser or search-service warnings continue

Reduce likelihood and impact

Practical steps

  1. 01

    Preserve context first

    Record alerts, times and recent changes and preserve relevant logs or snapshots before an automated clean-up alters evidence.

  2. 02

    Scan from more than one layer

    Compare public responses, application files, databases, accounts, scheduled jobs and provider signals where authorised and appropriate.

  3. 03

    Validate each finding

    Confirm why a file or behaviour is suspicious before deleting it, especially in customised applications.

  4. 04

    Find the access route

    Patch vulnerable code, remove persistence, rotate relevant credentials and tokens, and review connected hosting and administrator accounts.

  5. 05

    Prefer known-clean recovery

    For material compromise, rebuild or restore from trustworthy sources, verify functionality and increase monitoring after return to service.

Defined website support

How AHANIX can help

AHANIX can review website symptoms and perform scoped website file or application work, coordinating with the host or incident specialist.

  • Compare public symptoms with available website and provider information
  • Replace agreed website components from trusted sources where appropriate
  • Apply website updates and access changes identified by the wider investigation

Clear limits

What this cannot guarantee

  • No malware scanner can guarantee detection of every malicious file, account, database change, stolen credential or persistence mechanism.
  • AHANIX does not claim forensic certainty or certify a compromised server as clean; complex incidents need qualified incident-response support.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Malware scanning questions

Does a clean malware scan mean the website is safe?

No. It means that scanner did not find what it was able and configured to detect at that time. Accounts, databases, server configuration and new or hidden techniques may remain outside its view.

Should detected files be deleted immediately?

Not blindly. Preserve evidence where practical, validate the finding and understand whether a clean replacement exists. Deleting only the visible file may not remove persistence or the entry point.

What is the difference between an external and server-side scan?

An external scan sees what a visitor receives. A server-side scan can inspect available files and sometimes databases, but requires trusted access and still cannot see every connected system.

A scoped next step

Treat a scan result as evidence, not a verdict

AHANIX can review website symptoms and explain whether ordinary web remediation or specialist incident response is appropriate.

Discuss suspicious website activity

Continue in the Security Centre