@pbn_hosting_sl
oficina@pbnhostingsl.com

Malware Scan – What We Check And What To Do

Malware Scan – What We Check And What To Do

Every site you host with us is scanned for malware automatically every night, whatever its type – WordPress, Joomla, Drupal, PrestaShop, OpenCart, Grav, MediaWiki, PHP or static HTML. The results are on each site’s Malware scan tab, in plain words: what was found, why it matters and what to do.

💡 Official files are never reported
Before anything is shown to you, each flagged file is compared with the official published copy of WordPress, its plugins and themes, Joomla or Drupal. A file that is byte-for-byte identical to the official one is cleared automatically – so an update or a stock plugin file no longer raises a false alarm.

What the scan checks

  • Core files: whether the files of your CMS are the official ones for its version, and whether anything extra has been dropped into its system folders.
  • Hidden or disguised code: patterns that malware uses to hide itself (obfuscated code, back doors that hide a plugin or an administrator, and similar).
  • Known malware: every changed file, and every file of each site once a week, is checked against large, regularly updated open-source malware signature databases.
  • Programs running from your files: a program started from inside a site’s folder (for example a crypto-miner) is stopped at once.

Reading the Malware scan tab

Open your site, then Malware scan in the left menu. A green box means nothing was found. A red box lists each file that needs your attention, what kind of problem it is, when it was first found, and the buttons to deal with it.

A file marked Being checked by our team matched a broad rule that also matches some harmless files; a person checks it before anything happens, and you have nothing to do.

What to do when something is found

  1. Quarantine the file. It is moved aside, so the site stops loading it at once. Nothing is deleted: the file is kept safely and Restore puts it back exactly as it was.
  2. Repair core files (WordPress, Joomla, Drupal) puts back the official files of the same version. Your content, plugins, themes, uploads and settings are not touched.
  3. Change the passwords of the site’s administrators, and update or remove plugins and themes you no longer use – that is how malware usually gets in.
  4. Press Scan again to check the site straight away instead of waiting for the night scan. It usually takes one to five minutes.

If a core file was changed by you on purpose, press This is my change and it will not be reported again. Not sure a file is harmful? Press Ask support to check – we look at the file for you and reply by e-mail.

When a site is paused

To protect its visitors and the other sites on the server, a site whose malware is still there 7 days after it was first found is paused. The tab shows the date. A paused site opens again automatically once the files are cleaned (or quarantined) and the next scan finds nothing – press Scan again to speed that up.

What we never do

  • We never delete your files automatically.
  • We never show the contents of your files to anyone outside our support team.
  • We never clear a finding because of its file name alone – only when its content is identical to the official copy, or after a person has checked it.
Share this article: