I received a notification that my domain has been infected. What should I do?

Recently Updated

Question: I received an email notification that my domain has infected files. What should I do?

Affects: WebHosting | Linux Plesk Reseller Hosting


Malware scanning mechanism.

On our Plesk webservers, the antivirus software ImunifyAV checks the health of folders and files on a daily basis.

It checks if a file has been modified and if someone has managed to pass malicious code to a file on your website.

In the event that malicious files or code are detected, you will receive a notification.

I received a notification

You received a notification that one or more files are infected.

We log in to the Plesk panel where we maintain the hosting account.

We find the specific domain name.

We click on the ImunnifyAV icon

We will see a list of files that have been found to be infected.

By clicking on the "Clean" button, all files will be cleaned and placed in quarantine.

Warning. There are cases where some files have been incorrectly identified as infected.
In this case, if files were placed in quarantine that caused the website to break, you can click the "undo" button and return the files to their original position.
You can review the content of these files and either remove only the malicious code or if there is no malicious code, click the "Ignore" button so that the specific file is added to the whitelist.