How to Scan Your Hosting Account for Malware

Detect malicious code on your hosting account using cPanel scanners, file checks, and reputable external malware tools.

· Updated · 2,293 views

Malware can hide in your files, inject spam links, or redirect visitors without obvious signs. Scanning regularly helps you catch infections early before they damage your reputation or get your site blacklisted.

Use the cPanel Scanner

Many cPanel servers include a virus or malware scanner:

  1. Log in to cPanel.
  2. Look for Virus Scanner or ImunifyAV under the Security section.
  3. Choose Scan Entire Home Directory.
  4. Start the scan and wait for the results.
  5. Quarantine or remove any flagged files.

If you do not see a scanner, your account may use a server-side scan that runs automatically.

Watch for Warning Signs

  • Unexpected redirects to other sites.
  • Spam pages or links you did not create.
  • Sudden slowdowns or high resource usage.
  • Browser or search-engine warnings about your domain.

Check Files Manually

In File Manager, look for suspicious files:

| Clue | What to Check | | --- | --- | | Recently modified files | Sort by modification date | | Odd filenames | Random strings or hidden files | | Unknown PHP files | Files in uploads folders |

PHP files inside an uploads directory are almost always malicious and should be removed.

Clean Up After Detection

  • Back up the site before deleting anything.
  • Remove or replace infected files with clean originals.
  • Update all passwords, including cPanel, FTP, and database.
  • Update WordPress core, themes, and plugins.

After cleaning, run the scan again to confirm the account is clear. If reinfection keeps happening, an outdated plugin or stolen password is usually the entry point, so close that gap before restoring traffic.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.