Skip to main content

Malware abuse fix explanation

If you have received an abuse notification regarding malware on your hosting account, this means that potentially malicious files or code have been detected on your website.

To resolve the issue, the infected files need to be identified, reviewed, and removed or cleaned from your hosting account.

In the abuse ticket, we usually provide the malware details. So the abuse ticket should be reviewed as well.

Your cPanel hosting package includes ImunifyAV, which can scan your account and identify files that are likely to be infected.

Important: Imunify's scan results identify suspicious or infected files, but the files may need to be removed or cleaned manually by the account owner. Please do not delete files blindly, as some files may be legitimate parts of your website.

1. Log in to cPanel

Log in to your hosting account and open cPanel.

Depending on your hosting provider, you may access cPanel through your hosting client's area or directly using the cPanel login address provided by your hosting provider.

After logging in, locate the ImunifyAV.

2. Open ImunifyAV

In cPanel, find and open ImunifyAV:

Imunify will display information about potentially malicious files found in your hosting account.

3. Run a malware scan

Start a scan of your hosting account.

Depending on the size of your website, the scan may take some time.

When the scan is complete, review the results carefully.

You may see information such as:

  • The path and filename of the suspicious file

  • The type of detected malware

  • The detection status

  • The date when the file was detected

  • The location of the file within your hosting account

For example:

/home/account/public_html/wp-content/uploads/example.php

The path is important because it tells you where the suspicious file is located.

4. Review the detected files

Before deleting anything, check each detected file.

Pay particular attention to files located in:

  • public_html

  • Website upload directories

  • Temporary directories

  • WordPress uploads directories

  • Unknown or recently created directories

  • Directories containing unfamiliar PHP files

Malware is frequently hidden inside otherwise legitimate websites, so a suspicious file may not always have an obvious name.

Do not delete files simply because they are reported by name

Some files may be incorrectly detected or may be required by your website.

If you are unsure whether a file is legitimate, do not delete it immediately. Contact your developer and provide the full file path and ImunifyAV detection information.

5. Make a backup before making changes

Before manually removing files, it is strongly recommended to create a backup of the website.

You can use cPanel's available backup functionality or download the relevant website files and database.

Keep in mind that if the backup was created after the website was already compromised, it may also contain malicious files. Therefore, do not automatically restore an old backup without checking it first.

6. Remove or clean the infected files

Once you have confirmed that a file is malicious and is not required by your website, you can remove it.

You can normally do this using:

cPanel → File Manager

Navigate to the location reported by ImunifyAV.

For example:

public_html/example.php

Select the malicious file and delete it.

If the file is part of a legitimate application or CMS installation, such as WordPress, Joomla, Drupal, or another application, it may be preferable to replace the compromised file with a clean copy from the official application package rather than simply deleting it.

For example, if a core application file has been modified, replacing it with a fresh version can be safer than deleting the file.

7. Check for additional malicious files

Do not stop after removing the first detected file.

Review all files reported by ImunifyAV.

Attackers often place multiple malicious files on a compromised website. Removing only one file may leave the infection active.

Also check for:

  • Unknown PHP files

  • Recently created files that you do not recognize

  • Suspicious files in upload directories

  • Unexpected administrator accounts

  • Unknown cron jobs

  • Suspicious .htaccess changes

  • Modified website configuration files

  • Unknown plugins, themes, or extensions

If you use a CMS such as WordPress, also review installed plugins and themes and remove anything that you do not recognize or no longer use.

8. Update the website

After removing the malicious files, make sure the website software is fully updated.

For example, if you use WordPress, update:

  • WordPress itself

  • All installed plugins

  • All installed themes

Remove plugins, themes, or other software that are no longer maintained or are not being used.

An outdated plugin, theme, CMS, or other application may have been the original entry point for the malware.

9. Change your passwords

If your website has been compromised, assume that credentials may have been exposed.

We recommend changing passwords for:

  • cPanel

  • FTP/SFTP accounts

  • Website administrator accounts

  • CMS administrator accounts

  • Database users, where appropriate

  • Email accounts associated with the website

  • Other accounts that could have been used to access the hosting account

Use strong, unique passwords and enable two-factor authentication where available.

10. Scan the website again

After removing the suspicious files and making the necessary updates, run another ImunifyAV scan.

The purpose of the second scan is to confirm that the previously detected malware has been removed and that no additional malicious files remain.

If ImunifyAV continues to detect malware, do not assume that the original files were the only problem.

There may be:

  • Additional infected files

  • Backdoors

  • Modified legitimate files

  • Malicious code injected into existing files

  • Vulnerable software that is reinfecting the account

Further investigation may therefore be required.

Important: Do not ignore the abuse notification

If you have received an abuse notification, cleaning the detected files is only part of the process.

The underlying vulnerability should also be addressed. Otherwise, the website may become infected again.

After completing the cleanup:

  1. Remove or clean confirmed malicious files.

  2. Update the website and its components.

  3. Change relevant passwords.

  4. Run another malware scan.

  5. Confirm that the malware is no longer detected.

  6. Address the vulnerability that allowed the compromise.

  7. Inform Hostens abuse team in the abuse ticket that the cleanup has been completed. Please do not miss to do this otherwise the service will be suspended.

If you are not comfortable deleting files manually

Manually deleting website files can cause the website to stop working if legitimate files are removed.

If you are unsure about any detected file, do not delete it based solely on its filename. Save the ImunifyAV detection details and ask your website developer to review the file before taking action.

The hosting provider can generally assist with identifying the affected files and explaining the scan results, while the website owner or developer is responsible for reviewing the website's code and fixing application-level vulnerabilities.

Did this answer your question?