If you have received an abuse notification regarding malware on your hosting account, this means that potentially malicious files or code have been detected on your website.
To resolve the issue, the infected files need to be identified, reviewed, and removed or cleaned from your hosting account.
In the abuse ticket, we usually provide the malware details. So the abuse ticket should be reviewed as well.
Your cPanel hosting package includes ImunifyAV, which can scan your account and identify files that are likely to be infected.
Important: Imunify's scan results identify suspicious or infected files, but the files may need to be removed or cleaned manually by the account owner. Please do not delete files blindly, as some files may be legitimate parts of your website.
1. Log in to cPanel
Log in to your hosting account and open cPanel.
Depending on your hosting provider, you may access cPanel through your hosting client's area or directly using the cPanel login address provided by your hosting provider.
After logging in, locate the ImunifyAV.
2. Open ImunifyAV
In cPanel, find and open ImunifyAV:
Imunify will display information about potentially malicious files found in your hosting account.
3. Run a malware scan
Start a scan of your hosting account.
Depending on the size of your website, the scan may take some time.
When the scan is complete, review the results carefully.
You may see information such as:
The path and filename of the suspicious file
The type of detected malware
The detection status
The date when the file was detected
The location of the file within your hosting account
For example:
/home/account/public_html/wp-content/uploads/example.php
The path is important because it tells you where the suspicious file is located.
4. Review the detected files
Before deleting anything, check each detected file.
Pay particular attention to files located in:
public_htmlWebsite upload directories
Temporary directories
WordPress
uploadsdirectoriesUnknown or recently created directories
Directories containing unfamiliar PHP files
Malware is frequently hidden inside otherwise legitimate websites, so a suspicious file may not always have an obvious name.
Do not delete files simply because they are reported by name
Some files may be incorrectly detected or may be required by your website.
If you are unsure whether a file is legitimate, do not delete it immediately. Contact your developer and provide the full file path and ImunifyAV detection information.
5. Make a backup before making changes
Before manually removing files, it is strongly recommended to create a backup of the website.
You can use cPanel's available backup functionality or download the relevant website files and database.
Keep in mind that if the backup was created after the website was already compromised, it may also contain malicious files. Therefore, do not automatically restore an old backup without checking it first.
6. Remove or clean the infected files
Once you have confirmed that a file is malicious and is not required by your website, you can remove it.
You can normally do this using:
cPanel → File Manager
Navigate to the location reported by ImunifyAV.
For example:
public_html/example.php
Select the malicious file and delete it.
If the file is part of a legitimate application or CMS installation, such as WordPress, Joomla, Drupal, or another application, it may be preferable to replace the compromised file with a clean copy from the official application package rather than simply deleting it.
For example, if a core application file has been modified, replacing it with a fresh version can be safer than deleting the file.
7. Check for additional malicious files
Do not stop after removing the first detected file.
Review all files reported by ImunifyAV.
Attackers often place multiple malicious files on a compromised website. Removing only one file may leave the infection active.
Also check for:
Unknown PHP files
Recently created files that you do not recognize
Suspicious files in upload directories
Unexpected administrator accounts
Unknown cron jobs
Suspicious
.htaccesschangesModified website configuration files
Unknown plugins, themes, or extensions
If you use a CMS such as WordPress, also review installed plugins and themes and remove anything that you do not recognize or no longer use.
8. Update the website
After removing the malicious files, make sure the website software is fully updated.
For example, if you use WordPress, update:
WordPress itself
All installed plugins
All installed themes
Remove plugins, themes, or other software that are no longer maintained or are not being used.
An outdated plugin, theme, CMS, or other application may have been the original entry point for the malware.
9. Change your passwords
If your website has been compromised, assume that credentials may have been exposed.
We recommend changing passwords for:
cPanel
FTP/SFTP accounts
Website administrator accounts
CMS administrator accounts
Database users, where appropriate
Email accounts associated with the website
Other accounts that could have been used to access the hosting account
Use strong, unique passwords and enable two-factor authentication where available.
10. Scan the website again
After removing the suspicious files and making the necessary updates, run another ImunifyAV scan.
The purpose of the second scan is to confirm that the previously detected malware has been removed and that no additional malicious files remain.
If ImunifyAV continues to detect malware, do not assume that the original files were the only problem.
There may be:
Additional infected files
Backdoors
Modified legitimate files
Malicious code injected into existing files
Vulnerable software that is reinfecting the account
Further investigation may therefore be required.
Important: Do not ignore the abuse notification
If you have received an abuse notification, cleaning the detected files is only part of the process.
The underlying vulnerability should also be addressed. Otherwise, the website may become infected again.
After completing the cleanup:
Remove or clean confirmed malicious files.
Update the website and its components.
Change relevant passwords.
Run another malware scan.
Confirm that the malware is no longer detected.
Address the vulnerability that allowed the compromise.
Inform Hostens abuse team in the abuse ticket that the cleanup has been completed. Please do not miss to do this otherwise the service will be suspended.
If you are not comfortable deleting files manually
Manually deleting website files can cause the website to stop working if legitimate files are removed.
If you are unsure about any detected file, do not delete it based solely on its filename. Save the ImunifyAV detection details and ask your website developer to review the file before taking action.
The hosting provider can generally assist with identifying the affected files and explaining the scan results, while the website owner or developer is responsible for reviewing the website's code and fixing application-level vulnerabilities.

