Knowledgebase

Scanning Your Account for Malware Print

  • securityabuse, security, malware, php, cpanel, plugins, themes, uploads, wordpress, backup
  • 0

ImunifyAV in cPanel scans your entire hosting account, independently of anything installed inside your website.

RUNNING A SCAN

  1. cPanel > ImunifyAV under Security.
  2. Click Start Scanning and scan the full home directory.
  3. Wait. Large accounts take several minutes.
  4. Review the Malicious tab.

READING RESULTS

Each detection shows the file path and the signature matched. Typical findings are obfuscated PHP in theme files, unknown PHP inside uploads folders, and modified core files.

ACTING ON DETECTIONS

  • Core application files: do not edit them. Replace with fresh copies from the official source.
  • Plugin or theme files: delete the extension entirely and reinstall from a legitimate source.
  • Unknown PHP in an uploads folder: safe to delete.
  • Anything you are unsure about: open a ticket before deleting. Removing the wrong file takes the site offline.

Download a backup before deleting anything. False positives do occur, particularly with heavily obfuscated or licence-protected premium plugins.

A SECOND OPINION

Install a scanner inside the application as well, such as Wordfence for WordPress, which compares core files against the official repository. Two different scanners catch different things.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot