ImunifyAV scans your whole hosting account for malware, backdoors and injected code, independently of anything installed inside your website.
RUNNING A SCAN
- In cPanel open ImunifyAV under Security.
- Click "Start Scanning" and scan the full home directory.
- Wait for it to finish. Large accounts take several minutes.
- Review the Malicious tab.
ACTING ON RESULTS
Core application files (WordPress core, for example): do not edit them, replace them with fresh copies from the official source.
- Plugin or theme files: delete the extension entirely and reinstall from a legitimate source.
- Unknown PHP files inside an uploads folder: safe to delete. Nothing legitimate puts PHP there.
- Anything you are unsure of: open a ticket before deleting.
Always download a backup before deleting flagged files. False positives happen with heavily obfuscated or licence-protected premium plugins.
AFTER CLEANING
A clean scan is not the end. Change all passwords, update everything, remove any nulled software, and review file permissions. A site cleaned but not hardened is usually reinfected within days.
If the scan finds widespread infection, open a ticket. We can advise and check whether other accounts or sites are affected.