1. Home
  2. Security
  3. Pair Malware Security
  4. Understanding Malware Types and Scan Results

Understanding Malware Types and Scan Results

Pair Malware Security monitors the files in your Pair hosting account for malware and potentially risky software. When it detects a threat, the result may include several labels. Each label answers a different question: 

  • Malware type: What is the malware designed to do?
  • File classification: Is the entire file harmful, or was a legitimate file modified?
  • File status: What action was taken after the file was detected? 

For example, a web shell may be classified as “Malicious” and have a status of “Quarantined.” A legitimate WordPress file containing malicious redirect code may be classified as “Compromised” and have a status of “Cleaned.” 

Understanding these differences will help you interpret the results shown in the Pair Malware Security interface. 

Malware Types

The malware type describes the threat’s behavior or purpose. A single website compromise may involve several malware types, each serving a different role. For example, an attacker may use an uploader to install a web shell, then use the web shell to install a mailer or inject a malicious redirect. 

Phishing

Phishing content imitates a legitimate website to trick visitors into entering passwords, payment details, or other sensitive information. 

Attackers sometimes hide phishing pages in a compromised hosting account unrelated to the organization being impersonated. Your website may appear unchanged because victims reach the phishing page through a direct link in a fraudulent email or on another compromised website. If the page is discovered, browsers, search engines, security services, and email providers may block the domain. 

Malicious Redirects

A malicious redirect sends visitors to a website they did not intend to visit. The destination may contain scams, phishing pages, unwanted advertisements, adult content, or malware. 

Redirect code is often injected into a legitimate theme, plugin, configuration file, or other website file. In that case, Pair Malware Security may classify the affected file as “Compromised.” A separate file created only to redirect visitors may instead be classified as “Malicious.” 

Some redirects only affect certain visitors, devices, search-engine referrals, or geographic locations. This can make the problem difficult to reproduce consistently. 

Web Shells and Backdoors

A web shell is a hidden control panel or command interface that lets an attacker access and control a website or hosting account. 

A backdoor is any method designed to preserve unauthorized access. 

Attackers can use web shells and backdoors to browse or change files, run commands, create administrator accounts, steal information, or install additional malware. Removing only the visible symptoms of an infection may not be enough if a web shell or backdoor remains, because the attacker can use it to reinfect the site. 

Defacements

A defacement is an unauthorized change to the visible content or appearance of a website. Attackers may replace a home page, add messages or images, or alter existing content. 

Defacement describes the effect of an attack more than a specific type of malicious file. The underlying detection may appear as a web shell, a malicious file, or a compromised legitimate file rather than under a “Defacement” label. 

Crypto-mining Malware

Crypto-mining software uses your hosting account’s processing resources to generate cryptocurrency for someone else. It can cause high CPU usage, slow websites, resource-limit errors, or account instability. 

Depending on the file and its behavior, Pair Malware Security may categorize a miner as “Other” malware or classify it as “Potentially Unwanted Application (PUA).”

Mailers and Email Spam

A mailer is a script used to send large amounts of unsolicited or malicious email. Mailers may also send stolen information from your website to an attacker. 

Spam sent from your hosting account can generate abuse complaints and damage the reputation of your domain or mail server. As a result, legitimate messages from your domain may be rejected or placed in recipients’ spam folders. 

Adware

Adware displays or injects unwanted advertisements, sends visitors to advertising pages, manipulates search results, or generates fraudulent advertising traffic. It can harm visitors and may cause search engines, browsers, antivirus services, or advertising networks to flag the site. 

Uploaders

An uploader gives an attacker a way to place files in your hosting account. The attacker can then upload web shells, phishing pages, mailers, redirects, or other malware. 

An uploader is often one part of a larger infection. If one is found, review the other results in the Pair Malware Security interface and check whether unfamiliar files, themes, or administrator accounts have also appeared. 

Other Malware

Some threats do not fit neatly into one category or combine several behaviors. These detections may appear as “Other.” Examples can include code used to attack other websites, deliver malware to visitors, steal data, create proxies, or consume server resources. 

File Classifications

The classification describes the condition and intended purpose of the detected file. It does not describe what Pair Malware Security did with the file. 

Malicious

A “Malicious” file was created for a harmful purpose and has no necessary role on a healthy website. Standalone web shells, mailers, phishing files, and backdoors are common examples. 

Because the entire file is harmful, Pair Malware Security may quarantine it, delete it, or prevent it from running, depending on the configuration of your Pair hosting account. 

Compromised or Injected

A “Compromised” file is a legitimate file that an attacker modified by adding malicious code. It may also be described as “Injected.”

For example, an attacker could add a redirect to a valid index.php, wp-config.php, plugin, or theme file. Deleting the entire file could damage the website, so Pair Malware Security normally removes the injected code or replaces the file with a safe copy while preserving its legitimate function. 

The “Compromised” label applies to the affected file. It does not necessarily mean that every file in the hosting account is compromised. 

Potentially Unwanted Application (PUA)

A “Potentially Unwanted Application (PUA)” is software that is not always malicious, but can create a security or resource risk. Examples can include standalone file managers, database administration scripts, proxy tools, crypto-miners, or outdated software with known vulnerabilities. 

A PUA may have been intentionally installed by a developer. However, these tools can provide powerful access and are frequently abused by attackers. If you recognize the application, confirm that it is current, secured, and still required. 

File Statuses and Remediation Results

The status describes the current stage of detection or the action taken on the file. The statuses available to you may depend on the protection settings included with your Pair Malware Security plan. 

Discovered

“Discovered” means Pair Malware Security identified the file, but no remediation action is recorded. If the status does not update or the site is showing signs of infection, contact Pair support. 

Quarantined

“Quarantined” means a malicious file was moved to a secure, non-executable location so it cannot run from its original path. Quarantine isolates the entire file; it does not remove malicious code from inside that file. 

Do not restore a quarantined file unless you have confirmed that it is safe. Restoring an active threat can reinfect the website or hosting account. 

Deleted

“Deleted” means the malicious file was removed from the server. This action is typically appropriate for a file that has no legitimate purpose. 

Deletion addresses that specific file. It does not prove that the vulnerability or stolen credential used to place the file has been fixed. 

Cleaned or Overwritten

“Cleaned” means malicious code was removed from a compromised legitimate file, while the safe portion of the file was preserved. “Overwritten” means the affected file was replaced with a known-safe version. 

A “Cleaned” or “Overwritten” result applies only to the listed file. It does not necessarily mean that every threat in the account has been removed. Review the remaining results and confirm that the website is working as expected. 

Quarantined versus Cleaned

These statuses describe two different remediation methods:

StatusUsually applies to What happens
QuarantinedA fully malicious fileThe entire file is moved to a non-executable location. 
CleanedA legitimate file containing injected malwareThe malicious code is removed while the legitimate file is preserved. 

What to Do After Malware Detection

Pair Malware Security can contain or remove detected malware, but unless you have the Complete Security tier with human expert comprehensive website cleanup, it will not address the way the attacker gained access. You should address these access points so that the attacker cannot reinfect the site. 

  1. Review all detections and their statuses in the Pair Malware Security interface.
  2. Update your CMS, plugins, themes, and other website software (if applicable).
  3. Remove any unused plugins, themes, applications, or admin accounts (if applicable).
  4. Change passwords for hosting, CMS admin accounts, databases, FTP/SFTP, and SSH. If you change a database password, update the website’s configuration immediately. Use unique passwords and enable multifactor authentication where available. 
  5. Check that the website loads normally and no longer displays signs of malware. 

Repeated detections, recurring redirects or defacements, new admin accounts, or files that reappear after removal can indicate a persistent backdoor or an unresolved vulnerability. These cases may require a full site review and cleanup. 

Updated on October 9, 2026

Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support