Information on malware removal

Removing malware from your web application

What is malware?

Malware is the umbrella term for harmful software and programming code: hostile or intrusive code intended to steal information, spy on users or abuse systems, usually over an extended period and without anyone noticing. In a web application, malware can take the form of executable code, scripts, active content or modified files, hidden between the legitimate code of your application.

How does malware get into your web application?

The biggest cause of a malware infection is vulnerabilities in software and web applications, for example through an outdated content management system (CMS), vulnerable plugins or unsafe scripts. Such vulnerabilities are abused through an exploit: a piece of software that allows an attacker to bypass security, infect your application and gain control over it. Leaked credentials and insecure third-party integrations are also common entry points.

Urgent malware removal

A malware infection affects your services, your visitors and possibly your clients' data. Our security experts are specialized in finding and removing malware and can restore your web application on short notice, so your organization does not come to a standstill. For urgent work an urgency fee applies. Request a quote directly or give us a call.

"This site may harm your computer"

An infected web application leads to missed revenue, loss of client confidence and reputational damage, and Google may remove or block your domain from its search results. In addition, browsers show warnings to visitors as soon as malware has been detected, such as "This site may harm your computer" or "The site ahead contains malware". Sometimes attackers also visibly alter pages of your application.

Removing all malware

Our security experts investigate your web application using a combination of automated tooling and manual analysis. We determine the cause of the infection, remove all infected data and prevent reinfection. In doing so we check for vulnerabilities and security risks and remove malware, backdoors, trojans, Blackhat SEO spam, phishing components and defaced pages. This way your application is restored quickly, the damage stays limited and your organization can move on.

Extensive security check

Besides tracing and removing malicious content on your application or server, we check for malicious redirects, clickjacking, hidden iframes, SQL injections, cross-site scripting, SEO spam injections and other web application vulnerabilities. This structurally improves your security and considerably reduces the chance of a new infection.

From WordPress to any custom configuration

Whether your web application is built on a custom framework or on a standard system such as WordPress, Joomla, Drupal or Magento: with our specialist knowledge of both open source systems and custom builds, we quickly trace and remove the malware in your application, website or server.

Manual malware screening

It is difficult to identify where attackers have placed malware within a web application. Our experts therefore perform manual inspection of the source code to determine whether and where malware has been installed. Vulnerabilities, security risks and unusual scripts are filtered out in the process. We remove the malware from the server, repair the source code and prevent the same vulnerability from being abused again.

Keep your web application clean and secure

Recovery is the first step; structural resilience the second. With a periodic web application pentest you have vulnerabilities identified before an attacker finds them. If personal data may have been involved in the incident, an assessment in the context of the GDPR supports your substantiation towards the Dutch Data Protection Authority.