Emergency server help: get in touch

Imunify360 CLI: Scan, List and Clean Malware from the Command Line

imunify360-agent malware commands for 2026: queue scans, list detections, clean or restore files, manage the ignore list and report false positives.

Published 10 min read

Short answer: Queue a scan with imunify360-agent malware on-demand queue put /home/bob/public_html (the older on-demand start --path is deprecated in 8.x), watch it with malware on-demand status, and list detections with malware malicious list --user bob. Clean files by ID with malware malicious cleanup ID (or a whole account with malware user cleanup bob), undo with malware malicious restore-original ID, and handle false positives with malware malicious move-to-ignore ID plus submit false-positive. Back up the account before any cleanup.

Applies to Imunify360 and ImunifyAV 8.x on cPanel & WHM 11.138

We ran the help output for every command on this page, and the read-only list commands, on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138) on 7 October 2026. That server runs ImunifyAV 8.9.2, where imunify360-agent is the same malware CLI (it is a link to imunify-antivirus). We did not run a cleanup there: the lab has no infected files and free ImunifyAV does not clean. The cleanup behaviour is checked against the official Imunify360 documentation (linked below) on the same day.

Before you start: product, version and cleanup settings

The same malware commands exist in Imunify360, ImunifyAV+ and free ImunifyAV, but not every product can clean. Imunify’s ImunifyAV+ page lists detection only for free ImunifyAV, one-click cleanup for ImunifyAV+, and one-click plus automated cleanup for Imunify360. Check what you have:

imunify360-agent version
rpm -qa | grep -i imunify

Then look at the settings that decide what happens to an infected file. With the JSON config you can pick out the malware sections:

imunify360-agent config show --json | python3 -c 'import json,sys; d=json.load(sys.stdin); c=d.get("items",d); [print(k, json.dumps(c[k])) for k in ("MALWARE_SCANNING","MALWARE_CLEANUP")]'

The values that matter, as described in the Imunify360 config reference:

SettingMeaningOn our lab
MALWARE_SCANNING.default_actioncleanup cleans automatically when a file is detected; notify only lists itcleanup
MALWARE_SCANNING.try_restore_from_backup_firstRestore a clean copy from backup when one exists, before applying the default actionfalse
MALWARE_CLEANUP.trim_file_instead_of_removalFor a file that is malicious as a whole (a web shell), make it zero bytes instead of deleting ittrue
MALWARE_CLEANUP.keep_original_files_daysHow long the original infected file can be restored after cleanup (default 14 days)14

If default_action is cleanup on Imunify360, files may already have been cleaned before you run anything. That is why restore-original (below) matters.

Scan a path or an account on demand

In Imunify 8.x, malware on-demand start still works but its help text marks it deprecated in favour of the queue. Queue one or more paths:

imunify360-agent malware on-demand queue put /home/bob/public_html
imunify360-agent malware on-demand queue put "/home/bob/public_html" "/home/alice/public_html" --file-mask "*.php, *.js"
imunify360-agent malware on-demand queue put /home/bob --intensity low --scan-db

Useful options (all listed by malware on-demand queue put --help):

  • --file-mask and --ignore-mask: comma-separated patterns such as "*.php, *.js" or "*.log, *.tmp".
  • --intensity low|moderate|high: one setting that overrides the separate --intensity-cpu, --intensity-io and --intensity-ram limits. Use low on a busy shared server.
  • --scan-db / --no-scan-db: also scan databases (for example injected scripts in WordPress tables).
  • --follow-symlinks, --detect-elf and --prioritize.

To scan every account on the server at once, use imunify360-agent malware user scan. Then follow progress:

imunify360-agent malware on-demand status
imunify360-agent malware on-demand list --limit 5
imunify360-agent malware on-demand stop        # stop the current scan
imunify360-agent malware on-demand stop --all  # stop it and clear the queue

Real output from our lab (three account scans, nothing found; times are Unix timestamps):

queued: 0
status: stopped

COMPLETED   CREATED     DURATION  ERROR  PATH         RESOURCE_TYPE  SCAN_STATUS  SCAN_TYPE   SCANID                            STARTED     TOTAL  TOTAL_MALICIOUS  TOTAL_RESOURCES
1791273938  1791273925  13        None   /home/site2  file           stopped      background  e9c7439257554c09a271b1c156cf74de  1791273925  3815   0                3815
1791273925  1791273912  13        None   /home/site3  file           stopped      background  a46b9be856f7407296ed0e3c29f23068  1791273912  3815   0                3815

List malicious files and check what was found

malware malicious list returns every detection with an ID. You need those IDs for cleanup, restore and ignore. Narrow it down:

imunify360-agent malware malicious list --user bob --limit 100
imunify360-agent malware malicious list --search wp-content/uploads
imunify360-agent malware malicious list --by-status found
imunify360-agent malware malicious list --by-scan-id e9c7439257554c09a271b1c156cf74de --json
imunify360-agent malware malicious summary

The --by-status values listed by the help text are found, cleanup_pending, cleanup_started, cleanup_done, cleanup_removed, cleanup_requires_myimunify_protection, cleanup_restore_pending, cleanup_restore_started, restore_from_backup_started and restored_from_backup. For an account-level view, malware user list shows each user’s infected file and database counts:

ANALYST_STATUS  CLEANUP_STATUS  HOME         INFECTED  INFECTED_DB  SCAN_DATE   SCAN_ID                           SCAN_STATUS  USER
None            None            /home/site1  0         0            1791273912  c8d0bc7a5cb248eebe15ec36728c2611  stopped      site1
None            None            /home/site2  0         0            1791273938  e9c7439257554c09a271b1c156cf74de  stopped      site2

Before you clean, look at a suspicious file without opening it in an editor. malware read shows the content through the agent, and malware history list shows what happened to a path over time:

imunify360-agent malware read --path /home/bob/public_html/wp-content/uploads/x.php --limit 2000
imunify360-agent malware history list --search /home/bob/public_html --limit 20

Clean up malicious files

Back up first. Cleanup edits or empties live files. Take an account backup (JetBackup, WHM backup or pkgacct) before a bulk cleanup, and do not run cleanup-all on a server you have not reviewed.

Clean selected files by ID, one account, or everything:

imunify360-agent malware malicious cleanup 1201 1202 1203
imunify360-agent malware user cleanup bob
imunify360-agent malware malicious cleanup-all
imunify360-agent malware cleanup status

What cleanup does to a file

Imunify distinguishes two outcomes, which you see in the status column and in the UI:

  • Injected code removed (status cleanup_done, “Cleaned” in the UI): the malicious part is cut out and the rest of the file stays. Typical for a WordPress core or plugin file with code added to the top.
  • Content removed (status cleanup_removed): the whole file was malicious, such as a web shell. With trim_file_instead_of_removal on (the default on our lab), the file stays in place at zero bytes instead of being deleted, so includes that point at it do not cause fatal errors.

In both cases the original is kept for keep_original_files_days (14 days by default). To see exactly what changed in one file:

imunify360-agent malware malicious diff --id 1201

Undo a cleanup with restore-original

If a cleaned site breaks, put the original (infected) file back, then clean it by hand. You can restore single files or a whole account:

imunify360-agent malware malicious restore-original 1201
imunify360-agent malware user restore-original bob

This only works within the keep_original_files_days window. A cPanel support article describes the same effect after an ImunifyAV+ upgrade: files removed or replaced with zero-byte files, recovered with the restore feature. If the window has passed, restore the file from your own backup instead.

False positives and the malware ignore list

When a legitimate file is flagged, you have three tools. Pick the narrowest one:

GoalCommand
Stop flagging this one detected fileimunify360-agent malware malicious move-to-ignore 1201
Ignore a path before it is scanned (file or folder)imunify360-agent malware ignore add /home/bob/public_html/tools/report.php
Ignore a database rather than filesimunify360-agent malware ignore add --resource-type db …
See or undo ignore entriesimunify360-agent malware ignore list then malware ignore delete ID
Drop an entry from the list without touching the fileimunify360-agent malware malicious remove-from-list 1201

Imunify’s dashboard documentation warns that a file on the ignore list is no longer scanned at all, so never ignore a whole public_html to silence one detection. The default list on our lab only holds system paths:

ADDED_DATE  ID  PATH                             RESOURCE_TYPE
1791226562  1   /home/virtfs                     file
1791226562  2   /proc                            file
1791226562  3   /sys                             file
1791226562  4   /usr/share/cagefs-skeleton/proc  file

Then report the file so the signature can be fixed for everyone. false-positive requires a --reason (free text); false-negative, for malware the scanner missed, takes just the path:

imunify360-agent submit false-positive /home/bob/public_html/tools/report.php --reason "Internal reporting script, no remote input"
imunify360-agent submit false-negative /home/bob/public_html/wp-includes/x.php

These commands cover malware detections only. If ModSecurity/WAF rules block a legitimate request, that is a different false positive: see Imunify360 false positives: find the rule ID. To allow an admin’s IP through the firewall, use Imunify360 whitelist IP from the CLI.

Check that it worked

  1. Rescan the cleaned files: imunify360-agent malware rescan --files /home/bob/public_html/index.php.
  2. Nothing is left in the found state: imunify360-agent malware malicious list --user bob --by-status found returns no rows.
  3. The account shows zero infections: imunify360-agent malware user list --ids bob.
  4. The site still works: load the home page, log in to the admin area, and check the PHP error log for missing-file or syntax errors.
  5. It stays clean: run another on-demand scan a day later. Files that come back mean the entry point (a vulnerable plugin, a stolen password) is still open.

Common problems

  • “DEPRECATED” in the help for on-demand start. Switch scripts to malware on-demand queue put; the options are the same apart from paths being positional instead of --path.
  • Scan stays queued. Only a limited number of scans run in parallel (parallel_scans_limit was 1 on our lab). Check malware on-demand status and wait, or stop a long scan.
  • Cleanup does nothing. Free ImunifyAV detects but does not clean. On ImunifyAV+ or Imunify360, check malware cleanup status and the file’s status with malicious list --ids ID; if it shows cleanup_requires_myimunify_protection, the status name indicates the account needs MyImunify protection before the cleanup can run, so check that account’s protection setting in the Imunify UI.
  • WordPress shows a white screen after cleanup. A plugin file was emptied or partly removed. Restore the original, replace the plugin with a clean copy from wordpress.org, then clean the site properly (see clean a hacked WordPress site on cPanel).
  • Malware keeps coming back. Cleanup removes files, not the way in. Update everything, rotate passwords and look for the source; if root may be affected, follow the server compromised runbook.

Official documentation: Imunify360: command-line interface · Imunify360: config file description · Imunify360: dashboard (Malware Scanner)

Related: Imunify360 False Positives: Find the Rule ID and Fix It · Imunify360 Whitelist IP and Countries from the CLI: Commands · Clean a Hacked WordPress Site on cPanel: Step-by-Step · Server hacked: incident response runbook for Linux and cPanel · Imunify360 review: worth it on a shared cPanel server?

See also: Imunify360 False Positives: Find the Rule ID and Fix It · Clean a Hacked WordPress Site on cPanel: Step-by-Step · Imunify360 Whitelist IP and Countries from the CLI: Commands

Frequently asked questions

How do I start a malware scan with imunify360-agent?

Run imunify360-agent malware on-demand queue put followed by one or more paths, for example /home/bob/public_html. The older malware on-demand start –path still exists but is marked deprecated in Imunify 8.x.

Where do cleaned files go in Imunify360?

Imunify keeps the original infected file so you can restore it for the number of days set in MALWARE_CLEANUP.keep_original_files_days (14 by default). Use malware malicious restore-original with the file ID to put it back.

Why are some files zero bytes after an Imunify cleanup?

When a whole file is malicious, such as a web shell, and trim_file_instead_of_removal is enabled, Imunify empties the file instead of deleting it. That avoids fatal errors from code that still includes the path.

How do I stop Imunify360 flagging a legitimate file?

Use malware malicious move-to-ignore with the file ID, or malware ignore add with the exact path, then report it with submit false-positive and a reason. Keep ignore entries as narrow as possible because ignored files are not scanned.

Can free ImunifyAV clean malware from the command line?

No. The malware commands exist, but the free product only detects. Cleanup needs ImunifyAV+ or Imunify360.

Does Imunify360 scan databases?

Yes, when database scanning is enabled. On-demand scans accept –scan-db, and the ignore list can hold database entries with –resource-type db.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Imunify360 and ImunifyAV 8.x on cPanel & WHM 11.138
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.