Security

You cleaned the site and the virus came back? Backdoors are to blame

You cleaned the site and the virus came back? Backdoors are to blame

It is one of the most frustrating scenarios. The site gets infected, someone removes the malicious code, everything looks fine, and a few days later the infection returns. And again. The owner grabs their head thinking they have hit an exceptionally nasty virus. In reality the problem is different: someone left an open back door.

What a backdoor is

A backdoor (literally "back entrance") is a small, hidden piece of code that the attacker leaves on the site specifically so they can return, even after you remove the visible infection and change passwords. It is like a burglar who, once inside the house, quietly makes themselves a key to the side door. You can change the lock on the front door, and they still get in.

Removing the symptoms of an infection without removing the backdoor is like treating a fever without treating its cause. You feel relief for a moment, and then it all comes back.

Why backdoors are so hard to find

Attackers hide them cleverly:

  • they pretend to be ordinary files: named like WordPress or Joomla components (e.g. wp-config-backup.php, class-loader.php), so at first glance they look innocent,
  • they scatter across many places: not one file but several or a dozen, tucked into different folders and plugins,
  • they blend into existing code: sometimes it is just one line appended to a real theme file,
  • they sit in the database too: not only in files, which many "quick" cleanups miss.

Miss just one, and the attacker has a way back.

That is why DIY "quick cleaning" often fails

The most common mistake is removing what is visible (e.g. spam in the content), convinced the matter is settled. Meanwhile the real work is something else: combing the whole site and database for every back door and establishing how the attacker got in the first time. Without that second step, the hole they came through is still open.

How to genuinely break the cycle

Effectively curing a site is always the same elements, done properly:

  • Finding and closing the way in: an outdated plugin, a weak password, a pirated add-on, an old CMS version.
  • Finding all the backdoors: in files and in the database, not just the first obvious one.
  • Replacing the core and plugins with clean versions from official sources, instead of "fixing" infected files.
  • Changing all passwords (panel, hosting, FTP, database, email) after the cleanup.
  • Watching for a few days: if something remains, it usually shows up quickly.

When it is worth handing to a specialist

If your site catches an infection a second or third time, that is the best proof the backdoor is still there. That is the point where DIY attempts usually only prolong the problem. We handle this every day: we find all the doors, close the way in and bring the site to a state where the infection has no way to return.

Your site "will not heal"? Get in touch, we will break the cycle.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.