Applies to: All plans.
If malware has been found on your account, do not panic. Our server-side scanner (ImunifyAV) detects malicious files and reports them to us, and we pass the details on to you. Your job now is to clean or restore the affected files, change your passwords, and close the hole that let the malware in. This article walks you through each step.
Note: Our scanner detects and reports — it does not clean your files for you, and there is no scan you can start yourself from cPanel. If you suspect an infection, contact support and we will check the server-side results for your account.
On Managed plans, our team monitors these alerts and will usually act for you. On Self-Managed, the steps below are yours to run — start a chat with us if you get stuck.
Symptoms
- A message from us says malware was detected on your account.
- A page or plugin stops working after a suspect file is removed or renamed.
- Your browser or Google shows a "deceptive site" / "this site may be hacked" warning.
- Unexpected spam appears to send from your domain, or your site redirects strangers to other sites.
Common causes (most likely first)
- Out-of-date software — an old WordPress core, theme or plugin with a known vulnerability. This is by far the most common cause.
- A weak or reused password for cPanel, WordPress or FTP that was guessed or leaked.
- A nulled / pirated theme or plugin that shipped with a backdoor.
- A compromised computer uploading infected files over FTP.
Quick fixes
Work through these in order.
1. Get the list of flagged files
Scanning runs at server level, so the findings come from us rather than from a panel you log into. Start a chat or open a ticket with your domain, and ask for the detected file paths and the date they were first seen. We will send you the list.
Result: You know exactly which files are infected and roughly when the infection started — which is what tells you how far back to restore.
2. Clean or restore the files
You have two routes — pick the one that fits.
- Restore a known-good copy (usually the fastest). Roll back to a backup from before the infection date. We back up with JetBackup to Backblaze B2. In cPanel -> Files -> JetBackup you can restore a file or folder, a database, or the full account.
- Clean in place. For a small number of files you can fix them by hand: in cPanel -> Files -> File Manager (or over SFTP) delete the injected files, and replace any modified core, theme or plugin files with fresh copies downloaded from the vendor. Reinstalling WordPress core and every plugin from scratch is safer than editing the infected files. Take a backup of the current state first, so nothing is lost if you delete too much.
Result: The malware is removed and your site is running clean files again.
Backup retention depends on your plan: Self-Managed Lite keeps a weekly self-restore point, Self-Managed Plus 7 days, Self-Managed Pro 14 days, and Managed keeps 30 days off-site. Pick a point that pre-dates the infection. If you are unsure, contact support before restoring.
3. Change every password
Malware often leaves stolen credentials behind, so rotate them all:
- cPanel — see How to reset your cPanel password.
- Client area — change it from the account/profile menu (top right) and turn on two-factor authentication.
- WordPress (or your app) admin users — reset every administrator password and delete any admin account you do not recognise.
- FTP/SFTP accounts and any database users tied to the site.
4. Update everything
Update your WordPress core, all themes and all plugins to the latest versions, and remove anything you are not using. Delete any nulled or pirated extensions outright.
If that did not work
- The same file keeps coming back. That is a sign of a backdoor or a reinfecting cron job. Restore from a clean backup point that pre-dates the first alert, then update and re-secure before bringing the site back.
- You deleted a file your site needs. Restore that single file from a JetBackup restore point, or reinstall the theme or plugin it belonged to from the vendor's own download.
- You are on Managed, or you are not sure what to do. Contact us. On Managed we will investigate and clean the site for you. On Self-Managed we will point you to the right backup and steps.
When you contact us, include your domain, the exact alert text, and the date the problem started — see What to include when you contact support.
Prevent reinfection
- Keep WordPress, themes and plugins updated — set up auto-updates where you can.
- Use long, unique passwords everywhere and enable 2FA on your client area and cPanel.
- Harden your site (see the related articles below) and keep your own off-site backup as well as ours.
- Never install nulled or pirated software.
Comments
0 comments
Please sign in to leave a comment.