+254725682556 +254725052660 info@ziprof.co.ke
Client Area

Security

How to Scan Your Website for Malware Using ClamAV (cPanel and DirectAdmin)

If your website is acting strangely, such as showing unfamiliar links, redirecting visitors to other sites, or triggering a "this site may be hacked" warning in search results, the first thing to check is whether malicious files have been uploaded to your hosting account. Your control panel includes a free virus scanner called ClamAV that checks your files for known malware signatures. Here's how to use it.

What ClamAV Does

ClamAV scans the files in your hosting account and compares them against a database of known malware signatures. It's useful for catching malicious scripts that get uploaded through outdated plugins, weak passwords, or compromised themes. It will not catch every type of infection, especially newly written malware, but it's a good first check.

Signs You Should Run a Scan

  • Your website redirects visitors to an unfamiliar site.
  • You notice new files or folders you didn't create, especially with strange names.
  • Your hosting account is sending spam email you didn't send.
  • Google Search Console or your browser flags your site as unsafe.
  • Your site suddenly loads slowly or your bandwidth usage spikes without explanation.

How to Run a Scan

In cPanel

  1. Log in to your cPanel account.
  2. Scroll to the Advanced section and click Virus Scanner.
  3. Choose which area to scan, for example Scan Home Directory to check your entire account, or select a specific folder such as public_html if you only want to check your live website.
  4. Click Scan Now and wait for the scan to finish. Larger accounts with many files can take several minutes.
  5. Review the results. For each infected file, you can choose to Cure it (attempt to remove the malicious code) or Delete it entirely.
Only delete or cure files you don't recognize. If a flagged file is one of your website's core files and you're not sure whether removing it will break your site, take a backup first or ask your host for guidance before acting.

In DirectAdmin

Not every DirectAdmin installation ships with a virus scanner enabled by default, since it depends on which plugin your host has installed. If you have one available:

  1. Log in to DirectAdmin.
  2. Look under Extra Features or Advanced Features for an option named Malware Scanner or Virus Scanner.
  3. Select the directory you want checked and start the scan.
  4. Review the report and remove or quarantine any files it flags as infected.

If you don't see a scanner option in your DirectAdmin account, contact your hosting provider's support team. They can run a server-side scan on your account and tell you whether any infected files were found.

If Malware Is Found

  1. Note down which files were flagged before removing anything, in case you need to restore specific content afterward.
  2. Remove or cure the infected files.
  3. Change the passwords for your control panel, FTP accounts, and any CMS admin login (such as WordPress) immediately, since a compromised password is one of the most common ways malware gets uploaded in the first place.
  4. Update your website software, themes, and plugins to their latest versions, since outdated software is the most common entry point for infections.
  5. If the infection is widespread or keeps coming back after cleaning, restoring your site from a clean backup taken before the infection is often faster and safer than trying to clean every file by hand.

For help restoring a clean copy of your site, see How to Restore a Website Backup.