# Imunify360 CLI: Scan, List and Clean Malware from the Command Line

Source: https://srvscripts.com/guides/imunify360-cli-malware-cleanup/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Queue a scan with `imunify360-agent malware on-demand queue put /home/bob/public_html` (the older `on-demand start --path` is deprecated in 8.x), watch it with `malware on-demand status`, and list detections with `malware malicious list --user bob`. Clean files by ID with `malware malicious cleanup ID` (or a whole account with `malware user cleanup bob`), undo with `malware malicious restore-original ID`, and handle false positives with `malware malicious move-to-ignore ID` plus `submit false-positive`. Back up the account before any cleanup.

We ran the help output for every command on this page, and the read-only list commands, on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138) on 7 October 2026. That server runs ImunifyAV 8.9.2, where `imunify360-agent` is the same malware CLI (it is a link to `imunify-antivirus`). We did not run a cleanup there: the lab has no infected files and free ImunifyAV does not clean. The cleanup behaviour is checked against the official Imunify360 documentation (linked below) on the same day.

## Before you start: product, version and cleanup settings

The same `malware` commands exist in Imunify360, ImunifyAV+ and free ImunifyAV, but not every product can clean. Imunify’s [ImunifyAV+ page](https://imunify360.com/antivirus-plus) lists detection only for free ImunifyAV, one-click cleanup for ImunifyAV+, and one-click plus automated cleanup for Imunify360. Check what you have:

```
imunify360-agent version
rpm -qa | grep -i imunify
```

Then look at the settings that decide what happens to an infected file. With the JSON config you can pick out the malware sections:

```
imunify360-agent config show --json | python3 -c 'import json,sys; d=json.load(sys.stdin); c=d.get("items",d); [print(k, json.dumps(c[k])) for k in ("MALWARE_SCANNING","MALWARE_CLEANUP")]'
```

The values that matter, as described in the [Imunify360 config reference](https://docs.imunify360.com/config_file_description/):

| Setting | Meaning | On our lab |
| --- | --- | --- |
| MALWARE_SCANNING.default_action | cleanup cleans automatically when a file is detected; notify only lists it | cleanup |
| MALWARE_SCANNING.try_restore_from_backup_first | Restore a clean copy from backup when one exists, before applying the default action | false |
| MALWARE_CLEANUP.trim_file_instead_of_removal | For a file that is malicious as a whole (a web shell), make it zero bytes instead of deleting it | true |
| MALWARE_CLEANUP.keep_original_files_days | How long the original infected file can be restored after cleanup (default 14 days) | 14 |

If `default_action` is `cleanup` on Imunify360, files may already have been cleaned before you run anything. That is why restore-original (below) matters.

## Scan a path or an account on demand

In Imunify 8.x, `malware on-demand start` still works but its help text marks it deprecated in favour of the queue. Queue one or more paths:

```
imunify360-agent malware on-demand queue put /home/bob/public_html
imunify360-agent malware on-demand queue put "/home/bob/public_html" "/home/alice/public_html" --file-mask "*.php, *.js"
imunify360-agent malware on-demand queue put /home/bob --intensity low --scan-db
```

Useful options (all listed by `malware on-demand queue put --help`):

- `--file-mask` and `--ignore-mask`: comma-separated patterns such as `"*.php, *.js"` or `"*.log, *.tmp"`.

- `--intensity low|moderate|high`: one setting that overrides the separate `--intensity-cpu`, `--intensity-io` and `--intensity-ram` limits. Use `low` on a busy shared server.

- `--scan-db` / `--no-scan-db`: also scan databases (for example injected scripts in WordPress tables).

- `--follow-symlinks`, `--detect-elf` and `--prioritize`.

To scan every account on the server at once, use `imunify360-agent malware user scan`. Then follow progress:

```
imunify360-agent malware on-demand status
imunify360-agent malware on-demand list --limit 5
imunify360-agent malware on-demand stop        # stop the current scan
imunify360-agent malware on-demand stop --all  # stop it and clear the queue
```

Real output from our lab (three account scans, nothing found; times are Unix timestamps):

```
queued: 0
status: stopped

COMPLETED   CREATED     DURATION  ERROR  PATH         RESOURCE_TYPE  SCAN_STATUS  SCAN_TYPE   SCANID                            STARTED     TOTAL  TOTAL_MALICIOUS  TOTAL_RESOURCES
1791273938  1791273925  13        None   /home/site2  file           stopped      background  e9c7439257554c09a271b1c156cf74de  1791273925  3815   0                3815
1791273925  1791273912  13        None   /home/site3  file           stopped      background  a46b9be856f7407296ed0e3c29f23068  1791273912  3815   0                3815
```

## List malicious files and check what was found

`malware malicious list` returns every detection with an ID. You need those IDs for cleanup, restore and ignore. Narrow it down:

```
imunify360-agent malware malicious list --user bob --limit 100
imunify360-agent malware malicious list --search wp-content/uploads
imunify360-agent malware malicious list --by-status found
imunify360-agent malware malicious list --by-scan-id e9c7439257554c09a271b1c156cf74de --json
imunify360-agent malware malicious summary
```

The `--by-status` values listed by the help text are `found`, `cleanup_pending`, `cleanup_started`, `cleanup_done`, `cleanup_removed`, `cleanup_requires_myimunify_protection`, `cleanup_restore_pending`, `cleanup_restore_started`, `restore_from_backup_started` and `restored_from_backup`. For an account-level view, `malware user list` shows each user’s infected file and database counts:

```
ANALYST_STATUS  CLEANUP_STATUS  HOME         INFECTED  INFECTED_DB  SCAN_DATE   SCAN_ID                           SCAN_STATUS  USER
None            None            /home/site1  0         0            1791273912  c8d0bc7a5cb248eebe15ec36728c2611  stopped      site1
None            None            /home/site2  0         0            1791273938  e9c7439257554c09a271b1c156cf74de  stopped      site2
```

Before you clean, look at a suspicious file without opening it in an editor. `malware read` shows the content through the agent, and `malware history list` shows what happened to a path over time:

```
imunify360-agent malware read --path /home/bob/public_html/wp-content/uploads/x.php --limit 2000
imunify360-agent malware history list --search /home/bob/public_html --limit 20
```

## Clean up malicious files

**Back up first.** Cleanup edits or empties live files. Take an account backup (JetBackup, WHM backup or `pkgacct`) before a bulk cleanup, and do not run `cleanup-all` on a server you have not reviewed.

Clean selected files by ID, one account, or everything:

```
imunify360-agent malware malicious cleanup 1201 1202 1203
imunify360-agent malware user cleanup bob
imunify360-agent malware malicious cleanup-all
imunify360-agent malware cleanup status
```

### What cleanup does to a file

Imunify distinguishes two outcomes, which you see in the status column and in the UI:

- **Injected code removed** (status `cleanup_done`, “Cleaned” in the UI): the malicious part is cut out and the rest of the file stays. Typical for a WordPress core or plugin file with code added to the top.

- **Content removed** (status `cleanup_removed`): the whole file was malicious, such as a web shell. With `trim_file_instead_of_removal` on (the default on our lab), the file stays in place at zero bytes instead of being deleted, so includes that point at it do not cause fatal errors.

In both cases the original is kept for `keep_original_files_days` (14 days by default). To see exactly what changed in one file:

```
imunify360-agent malware malicious diff --id 1201
```

## Undo a cleanup with restore-original

If a cleaned site breaks, put the original (infected) file back, then clean it by hand. You can restore single files or a whole account:

```
imunify360-agent malware malicious restore-original 1201
imunify360-agent malware user restore-original bob
```

This only works within the `keep_original_files_days` window. A cPanel support article describes the same effect after an ImunifyAV+ upgrade: files removed or replaced with zero-byte files, recovered with the restore feature. If the window has passed, restore the file from your own backup instead.

## False positives and the malware ignore list

When a legitimate file is flagged, you have three tools. Pick the narrowest one:

| Goal | Command |
| --- | --- |
| Stop flagging this one detected file | imunify360-agent malware malicious move-to-ignore 1201 |
| Ignore a path before it is scanned (file or folder) | imunify360-agent malware ignore add /home/bob/public_html/tools/report.php |
| Ignore a database rather than files | imunify360-agent malware ignore add --resource-type db … |
| See or undo ignore entries | imunify360-agent malware ignore list then malware ignore delete ID |
| Drop an entry from the list without touching the file | imunify360-agent malware malicious remove-from-list 1201 |

Imunify’s [dashboard documentation](https://docs.imunify360.com/dashboard/) warns that a file on the ignore list is no longer scanned at all, so never ignore a whole `public_html` to silence one detection. The default list on our lab only holds system paths:

```
ADDED_DATE  ID  PATH                             RESOURCE_TYPE
1791226562  1   /home/virtfs                     file
1791226562  2   /proc                            file
1791226562  3   /sys                             file
1791226562  4   /usr/share/cagefs-skeleton/proc  file
```

Then report the file so the signature can be fixed for everyone. `false-positive` requires a `--reason` (free text); `false-negative`, for malware the scanner missed, takes just the path:

```
imunify360-agent submit false-positive /home/bob/public_html/tools/report.php --reason "Internal reporting script, no remote input"
imunify360-agent submit false-negative /home/bob/public_html/wp-includes/x.php
```

These commands cover malware detections only. If ModSecurity/WAF rules block a legitimate request, that is a different false positive: see [Imunify360 false positives: find the rule ID](/guides/imunify360-false-positives/). To allow an admin’s IP through the firewall, use [Imunify360 whitelist IP from the CLI](/guides/imunify360-whitelist-ip-cli/).

## Check that it worked

- Rescan the cleaned files: `imunify360-agent malware rescan --files /home/bob/public_html/index.php`.

- Nothing is left in the found state: `imunify360-agent malware malicious list --user bob --by-status found` returns no rows.

- The account shows zero infections: `imunify360-agent malware user list --ids bob`.

- The site still works: load the home page, log in to the admin area, and check the PHP error log for missing-file or syntax errors.

- It stays clean: run another on-demand scan a day later. Files that come back mean the entry point (a vulnerable plugin, a stolen password) is still open.

## Common problems

- **“DEPRECATED” in the help for on-demand start.** Switch scripts to `malware on-demand queue put`; the options are the same apart from paths being positional instead of `--path`.

- **Scan stays queued.** Only a limited number of scans run in parallel (`parallel_scans_limit` was 1 on our lab). Check `malware on-demand status` and wait, or stop a long scan.

- **Cleanup does nothing.** Free ImunifyAV detects but does not clean. On ImunifyAV+ or Imunify360, check `malware cleanup status` and the file’s status with `malicious list --ids ID`; if it shows `cleanup_requires_myimunify_protection`, the status name indicates the account needs MyImunify protection before the cleanup can run, so check that account’s protection setting in the Imunify UI.

- **WordPress shows a white screen after cleanup.** A plugin file was emptied or partly removed. Restore the original, replace the plugin with a clean copy from wordpress.org, then clean the site properly (see [clean a hacked WordPress site on cPanel](/guides/clean-hacked-wordpress-cpanel/)).

- **Malware keeps coming back.** Cleanup removes files, not the way in. Update everything, rotate passwords and look for the source; if root may be affected, follow the [server compromised runbook](/guides/runbook-server-compromised/).

**Official documentation:** [Imunify360: command-line interface](https://docs.imunify360.com/command_line_interface/) · [Imunify360: config file description](https://docs.imunify360.com/config_file_description/) · [Imunify360: dashboard (Malware Scanner)](https://docs.imunify360.com/dashboard/)

**Related:** [Imunify360 False Positives: Find the Rule ID and Fix It](/guides/imunify360-false-positives/) · [Imunify360 Whitelist IP and Countries from the CLI: Commands](/guides/imunify360-whitelist-ip-cli/) · [Clean a Hacked WordPress Site on cPanel: Step-by-Step](/guides/clean-hacked-wordpress-cpanel/) · [Server hacked: incident response runbook for Linux and cPanel](/guides/runbook-server-compromised/) · [Imunify360 review: worth it on a shared cPanel server?](/reviews/imunify360-review/)

**See also:** [Imunify360 False Positives: Find the Rule ID and Fix It](/guides/imunify360-false-positives/) · [Clean a Hacked WordPress Site on cPanel: Step-by-Step](/guides/clean-hacked-wordpress-cpanel/) · [Imunify360 Whitelist IP and Countries from the CLI: Commands](/guides/imunify360-whitelist-ip-cli/)

## Frequently asked questions

### How do I start a malware scan with imunify360-agent?

Run imunify360-agent malware on-demand queue put followed by one or more paths, for example /home/bob/public_html. The older malware on-demand start –path still exists but is marked deprecated in Imunify 8.x.

### Where do cleaned files go in Imunify360?

Imunify keeps the original infected file so you can restore it for the number of days set in MALWARE_CLEANUP.keep_original_files_days (14 by default). Use malware malicious restore-original with the file ID to put it back.

### Why are some files zero bytes after an Imunify cleanup?

When a whole file is malicious, such as a web shell, and trim_file_instead_of_removal is enabled, Imunify empties the file instead of deleting it. That avoids fatal errors from code that still includes the path.

### How do I stop Imunify360 flagging a legitimate file?

Use malware malicious move-to-ignore with the file ID, or malware ignore add with the exact path, then report it with submit false-positive and a reason. Keep ignore entries as narrow as possible because ignored files are not scanned.

### Can free ImunifyAV clean malware from the command line?

No. The malware commands exist, but the free product only detects. Cleanup needs ImunifyAV+ or Imunify360.

### Does Imunify360 scan databases?

Yes, when database scanning is enabled. On-demand scans accept –scan-db, and the ignore list can hold database entries with –resource-type db.
