Short answer: Queue a scan with imunify360-agent malware on-demand queue put /home/bob/public_html (the older on-demand start --path is deprecated in 8.x), watch it with malware on-demand status, and list detections with malware malicious list --user bob. Clean files by ID with malware malicious cleanup ID (or a whole account with malware user cleanup bob), undo with malware malicious restore-original ID, and handle false positives with malware malicious move-to-ignore ID plus submit false-positive. Back up the account before any cleanup.
Applies to Imunify360 and ImunifyAV 8.x on cPanel & WHM 11.138
We ran the help output for every command on this page, and the read-only list commands, on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138) on 7 October 2026. That server runs ImunifyAV 8.9.2, where imunify360-agent is the same malware CLI (it is a link to imunify-antivirus). We did not run a cleanup there: the lab has no infected files and free ImunifyAV does not clean. The cleanup behaviour is checked against the official Imunify360 documentation (linked below) on the same day.
Table of Contents
Before you start: product, version and cleanup settings
The same malware commands exist in Imunify360, ImunifyAV+ and free ImunifyAV, but not every product can clean. Imunify’s ImunifyAV+ page lists detection only for free ImunifyAV, one-click cleanup for ImunifyAV+, and one-click plus automated cleanup for Imunify360. Check what you have:
imunify360-agent version
rpm -qa | grep -i imunify
Then look at the settings that decide what happens to an infected file. With the JSON config you can pick out the malware sections:
imunify360-agent config show --json | python3 -c 'import json,sys; d=json.load(sys.stdin); c=d.get("items",d); [print(k, json.dumps(c[k])) for k in ("MALWARE_SCANNING","MALWARE_CLEANUP")]'
The values that matter, as described in the Imunify360 config reference:
| Setting | Meaning | On our lab |
|---|---|---|
MALWARE_SCANNING.default_action | cleanup cleans automatically when a file is detected; notify only lists it | cleanup |
MALWARE_SCANNING.try_restore_from_backup_first | Restore a clean copy from backup when one exists, before applying the default action | false |
MALWARE_CLEANUP.trim_file_instead_of_removal | For a file that is malicious as a whole (a web shell), make it zero bytes instead of deleting it | true |
MALWARE_CLEANUP.keep_original_files_days | How long the original infected file can be restored after cleanup (default 14 days) | 14 |
If default_action is cleanup on Imunify360, files may already have been cleaned before you run anything. That is why restore-original (below) matters.
Scan a path or an account on demand
In Imunify 8.x, malware on-demand start still works but its help text marks it deprecated in favour of the queue. Queue one or more paths:
imunify360-agent malware on-demand queue put /home/bob/public_html
imunify360-agent malware on-demand queue put "/home/bob/public_html" "/home/alice/public_html" --file-mask "*.php, *.js"
imunify360-agent malware on-demand queue put /home/bob --intensity low --scan-db
Useful options (all listed by malware on-demand queue put --help):
--file-maskand--ignore-mask: comma-separated patterns such as"*.php, *.js"or"*.log, *.tmp".--intensity low|moderate|high: one setting that overrides the separate--intensity-cpu,--intensity-ioand--intensity-ramlimits. Uselowon a busy shared server.--scan-db/--no-scan-db: also scan databases (for example injected scripts in WordPress tables).--follow-symlinks,--detect-elfand--prioritize.
To scan every account on the server at once, use imunify360-agent malware user scan. Then follow progress:
imunify360-agent malware on-demand status
imunify360-agent malware on-demand list --limit 5
imunify360-agent malware on-demand stop # stop the current scan
imunify360-agent malware on-demand stop --all # stop it and clear the queue
Real output from our lab (three account scans, nothing found; times are Unix timestamps):
queued: 0
status: stopped
COMPLETED CREATED DURATION ERROR PATH RESOURCE_TYPE SCAN_STATUS SCAN_TYPE SCANID STARTED TOTAL TOTAL_MALICIOUS TOTAL_RESOURCES
1791273938 1791273925 13 None /home/site2 file stopped background e9c7439257554c09a271b1c156cf74de 1791273925 3815 0 3815
1791273925 1791273912 13 None /home/site3 file stopped background a46b9be856f7407296ed0e3c29f23068 1791273912 3815 0 3815
List malicious files and check what was found
malware malicious list returns every detection with an ID. You need those IDs for cleanup, restore and ignore. Narrow it down:
imunify360-agent malware malicious list --user bob --limit 100
imunify360-agent malware malicious list --search wp-content/uploads
imunify360-agent malware malicious list --by-status found
imunify360-agent malware malicious list --by-scan-id e9c7439257554c09a271b1c156cf74de --json
imunify360-agent malware malicious summary
The --by-status values listed by the help text are found, cleanup_pending, cleanup_started, cleanup_done, cleanup_removed, cleanup_requires_myimunify_protection, cleanup_restore_pending, cleanup_restore_started, restore_from_backup_started and restored_from_backup. For an account-level view, malware user list shows each user’s infected file and database counts:
ANALYST_STATUS CLEANUP_STATUS HOME INFECTED INFECTED_DB SCAN_DATE SCAN_ID SCAN_STATUS USER
None None /home/site1 0 0 1791273912 c8d0bc7a5cb248eebe15ec36728c2611 stopped site1
None None /home/site2 0 0 1791273938 e9c7439257554c09a271b1c156cf74de stopped site2
Before you clean, look at a suspicious file without opening it in an editor. malware read shows the content through the agent, and malware history list shows what happened to a path over time:
imunify360-agent malware read --path /home/bob/public_html/wp-content/uploads/x.php --limit 2000
imunify360-agent malware history list --search /home/bob/public_html --limit 20
Clean up malicious files
Back up first. Cleanup edits or empties live files. Take an account backup (JetBackup, WHM backup or pkgacct) before a bulk cleanup, and do not run cleanup-all on a server you have not reviewed.
Clean selected files by ID, one account, or everything:
imunify360-agent malware malicious cleanup 1201 1202 1203
imunify360-agent malware user cleanup bob
imunify360-agent malware malicious cleanup-all
imunify360-agent malware cleanup status
What cleanup does to a file
Imunify distinguishes two outcomes, which you see in the status column and in the UI:
- Injected code removed (status
cleanup_done, “Cleaned” in the UI): the malicious part is cut out and the rest of the file stays. Typical for a WordPress core or plugin file with code added to the top. - Content removed (status
cleanup_removed): the whole file was malicious, such as a web shell. Withtrim_file_instead_of_removalon (the default on our lab), the file stays in place at zero bytes instead of being deleted, so includes that point at it do not cause fatal errors.
In both cases the original is kept for keep_original_files_days (14 days by default). To see exactly what changed in one file:
imunify360-agent malware malicious diff --id 1201
Undo a cleanup with restore-original
If a cleaned site breaks, put the original (infected) file back, then clean it by hand. You can restore single files or a whole account:
imunify360-agent malware malicious restore-original 1201
imunify360-agent malware user restore-original bob
This only works within the keep_original_files_days window. A cPanel support article describes the same effect after an ImunifyAV+ upgrade: files removed or replaced with zero-byte files, recovered with the restore feature. If the window has passed, restore the file from your own backup instead.
False positives and the malware ignore list
When a legitimate file is flagged, you have three tools. Pick the narrowest one:
| Goal | Command |
|---|---|
| Stop flagging this one detected file | imunify360-agent malware malicious move-to-ignore 1201 |
| Ignore a path before it is scanned (file or folder) | imunify360-agent malware ignore add /home/bob/public_html/tools/report.php |
| Ignore a database rather than files | imunify360-agent malware ignore add --resource-type db … |
| See or undo ignore entries | imunify360-agent malware ignore list then malware ignore delete ID |
| Drop an entry from the list without touching the file | imunify360-agent malware malicious remove-from-list 1201 |
Imunify’s dashboard documentation warns that a file on the ignore list is no longer scanned at all, so never ignore a whole public_html to silence one detection. The default list on our lab only holds system paths:
ADDED_DATE ID PATH RESOURCE_TYPE
1791226562 1 /home/virtfs file
1791226562 2 /proc file
1791226562 3 /sys file
1791226562 4 /usr/share/cagefs-skeleton/proc file
Then report the file so the signature can be fixed for everyone. false-positive requires a --reason (free text); false-negative, for malware the scanner missed, takes just the path:
imunify360-agent submit false-positive /home/bob/public_html/tools/report.php --reason "Internal reporting script, no remote input"
imunify360-agent submit false-negative /home/bob/public_html/wp-includes/x.php
These commands cover malware detections only. If ModSecurity/WAF rules block a legitimate request, that is a different false positive: see Imunify360 false positives: find the rule ID. To allow an admin’s IP through the firewall, use Imunify360 whitelist IP from the CLI.
Check that it worked
- Rescan the cleaned files:
imunify360-agent malware rescan --files /home/bob/public_html/index.php. - Nothing is left in the found state:
imunify360-agent malware malicious list --user bob --by-status foundreturns no rows. - The account shows zero infections:
imunify360-agent malware user list --ids bob. - The site still works: load the home page, log in to the admin area, and check the PHP error log for missing-file or syntax errors.
- It stays clean: run another on-demand scan a day later. Files that come back mean the entry point (a vulnerable plugin, a stolen password) is still open.
Common problems
- “DEPRECATED” in the help for on-demand start. Switch scripts to
malware on-demand queue put; the options are the same apart from paths being positional instead of--path. - Scan stays queued. Only a limited number of scans run in parallel (
parallel_scans_limitwas 1 on our lab). Checkmalware on-demand statusand wait, or stop a long scan. - Cleanup does nothing. Free ImunifyAV detects but does not clean. On ImunifyAV+ or Imunify360, check
malware cleanup statusand the file’s status withmalicious list --ids ID; if it showscleanup_requires_myimunify_protection, the status name indicates the account needs MyImunify protection before the cleanup can run, so check that account’s protection setting in the Imunify UI. - WordPress shows a white screen after cleanup. A plugin file was emptied or partly removed. Restore the original, replace the plugin with a clean copy from wordpress.org, then clean the site properly (see clean a hacked WordPress site on cPanel).
- Malware keeps coming back. Cleanup removes files, not the way in. Update everything, rotate passwords and look for the source; if root may be affected, follow the server compromised runbook.
Official documentation: Imunify360: command-line interface · Imunify360: config file description · Imunify360: dashboard (Malware Scanner)
Related: Imunify360 False Positives: Find the Rule ID and Fix It · Imunify360 Whitelist IP and Countries from the CLI: Commands · Clean a Hacked WordPress Site on cPanel: Step-by-Step · Server hacked: incident response runbook for Linux and cPanel · Imunify360 review: worth it on a shared cPanel server?
See also: Imunify360 False Positives: Find the Rule ID and Fix It · Clean a Hacked WordPress Site on cPanel: Step-by-Step · Imunify360 Whitelist IP and Countries from the CLI: Commands
Frequently asked questions
How do I start a malware scan with imunify360-agent?
Run imunify360-agent malware on-demand queue put followed by one or more paths, for example /home/bob/public_html. The older malware on-demand start –path still exists but is marked deprecated in Imunify 8.x.
Where do cleaned files go in Imunify360?
Imunify keeps the original infected file so you can restore it for the number of days set in MALWARE_CLEANUP.keep_original_files_days (14 by default). Use malware malicious restore-original with the file ID to put it back.
Why are some files zero bytes after an Imunify cleanup?
When a whole file is malicious, such as a web shell, and trim_file_instead_of_removal is enabled, Imunify empties the file instead of deleting it. That avoids fatal errors from code that still includes the path.
How do I stop Imunify360 flagging a legitimate file?
Use malware malicious move-to-ignore with the file ID, or malware ignore add with the exact path, then report it with submit false-positive and a reason. Keep ignore entries as narrow as possible because ignored files are not scanned.
Can free ImunifyAV clean malware from the command line?
No. The malware commands exist, but the free product only detects. Cleanup needs ImunifyAV+ or Imunify360.
Does Imunify360 scan databases?
Yes, when database scanning is enabled. On-demand scans accept –scan-db, and the ignore list can hold database entries with –resource-type db.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Imunify360 and ImunifyAV 8.x on cPanel & WHM 11.138
- Last full review
- Next review