Where persistence hides.
WHY THIS MATTERS
Attackers use scheduled tasks to reinstate themselves after cleanup.
That is why sites are cleaned and compromised again days later.
WHAT TO CHECK
Every cron job in cPanel Scheduled tasks within your application
WHAT A MALICIOUS JOB LOOKS LIKE
A command downloading and running something An obscure file path Obfuscated content A schedule you did not set
WHAT TO DO
Remove anything you did not create.
If unsure, record it and ask us before removing.
FOR WORDPRESS
Scheduled events within the application can also be used.
A cron viewer plugin lists them.
Look for anything unfamiliar.
WHAT ELSE TO CHECK
Startup files Anything set to run automatically
WHY THIS STEP IS SKIPPED
Most cleanup guidance concentrates on files.
That is why cleanups fail.
WHAT TO DO AFTERWARDS
Recreate your legitimate cron jobs, if you removed them.