When you run a ClamAV scan on your hosting account and choose to quarantine infected files instead of deleting them, those files are moved out of your website's folders into a separate quarantine area. This keeps the malware from running while giving you a chance to review each file before deciding what to do with it. Here's how to find quarantined files and restore the ones that were flagged incorrectly.
Only restore a file if you're confident it's safe. If a scan flagged a file because it genuinely contains malicious code, restoring it will put the infected file straight back on your live website. If you're not sure why a file was flagged, it's safer to leave it quarantined and open a support ticket for a second opinion.
In cPanel
cPanel's Virus Scanner tool lets you choose what happens to infected files before you even run a scan, and it keeps a record of anything it quarantines.
- Log in to cPanel and open Virus Scanner under the Security section.
- Before starting a new scan, check the Actions to Take dropdown for the directory you're scanning. Choosing Quarantine the file(s) moves anything infected out of your website instead of deleting it outright.
- After the scan finishes, review the results list. Each quarantined file is shown with its original path.
- To bring a file back, locate it in the scan results and use the restore option next to that file, or note its listed original path so support can restore it for you.
- Once restored, re-scan the same directory to confirm the file no longer shows up as infected.
In DirectAdmin
DirectAdmin's ClamAV integration is more limited than cPanel's, and exactly how quarantine works can vary depending on which scanning plugin your account has. In most cases:
- Log in to DirectAdmin and open the malware or virus scanner section (its exact name varies, but it's usually listed under Extra Features or Advanced Features).
- Run a scan and check the results page. It will list any file that was flagged, along with the path it was moved to if quarantine was applied.
- If the scan report gives you a quarantine folder path, you can use File Manager to move the file back to its original location shown in the report.
- If you can't find a quarantine folder or restore option for your account, open a support ticket with the file's original path from the scan report so it can be restored on the server side.
Either way, once a file is restored, keep an eye on your site for a few days. If the same file gets flagged again on your next scan, treat it as a genuine infection rather than a false positive, and consider replacing it from a clean backup instead of restoring it again.
For a walkthrough of running the scan itself, see How to Scan Your Website for Malware Using ClamAV.